{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-98163","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-25T10:25:14.321Z","datePublished":"2026-09-26T08:31:50.899Z","dateUpdated":"2026-10-07T06:49:15.579Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-10-07T06:49:15.579Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ncgroup: Avoid iteration of dying tasks with zero refcount\n\nThe commit 260fbcb92bbea (\"cgroup: Move dying_tasks cleanup from\ncgroup_task_release() to cgroup_task_free()\") extended the lifetime of\ntasks on the dying_tasks list.\nThe iterators have provision to go through dying_tasks because of\ndying threadgroup leaders or explicit CSS_TASK_ITER_WITH_DEAD, however,\nit was expected that such tasks can obtain a new reference (that is\npossible before cgroup_task_release()/put_task_struct_rcu_user()).\nThe tasks after cgroup_task_release() and before cgroup_task_free()\nare subject to race when they may or may not have ->usage count > 0.\n\nThe race window is between css_task_iter_next() invocations\nwhen css_set_lock is released and we may arrive at a new ->task_pos.\nThe iterator should not attempt to resurrect tasks whose ->usage count\ndropped to zero. (When that happens, __put_task_struct_rcu_cb() is\nalready imminent and the returned task_struct would could be used\nafter free.)\n\nAs for the fix, we cannot simply check the signal->live count of a task\non the dying list because that won't distinguish regular zombies waiting\nto be reaped from RCU remnant tasks that are going to be free'd.\nTherefore add an extra check to rule out ->usage==0 tasks from any\niteration.\n\nThe repeat: loop in css_task_iter_advance() doesn't consider ->usage\ncount, so add a new loop to css_task_iter_next() to skip de-used tasks\non the dying_list.\n\nRough illustration of the possible race\n\n  R (reader of cgroup.procs)         T (thread)                       L (group leader)\n  ---------------------------------  -------------------------------- --------------------------------\n                                                                      L exits, signal->live > 0\n                                                                      cgroup_task_dead(L)\n                                                                        css_set_skip_task_iters() // skips only cset->tasks\n                                                                        list_add_tail(&L->cg_list, &cset->dying_tasks)\n  css_task_iter_next()\n    take css_set_lock\n    css_task_iter_advance()\n      leader && signal->live != 0\n      => it->task_pos = &L->cg_list\n    release css_set_lock\n                                     T exits\n                                     --signal->live == 0\n\t\t\t\t     cgroup_task_dead(T) // css_set_lock\n                                     release_task(T)\n                                       cgroup_task_release(T)\n                                       release_task(L) // zap_leader\n                                         cgroup_task_release(L)\n                                         put_task_struct_rcu_user(L)\n                                         ...RCU...\n                                         put_task_struct(L)\n                                           L->usage = 0\n                                           /* L still on dying_tasks */\n                                           ...RCU...\n                                           __put_task_struct(L)\n  css_task_iter_next() // another iteration\n    take css_set_lock\n    it->task_pos = &L->cg_list\n    get_task_struct(L)\n      => addition on 0\n    drop css_set_lock\n                                           cgroup_task_free(L)\n                                             css_set_skip_task_iters() // dying skip comes too late\n                                           free_task(L)\n  cgroup_procs_show()\n    task_pid_vnr(L)"}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The bug is in css_task_iter_next() (kernel/cgroup/cgroup.c), reached by a local read() of a cgroup.procs/cgroup.threads seq file via cgroup_procs_start/next/show. No remote peer supplies any input to this path.\nAC:L - The attacker controls both sides of the race: one thread repeatedly reads its own cgroup.procs while the attacker's own multithreaded process exits its group leader and then its last thread, dropping the leader's ->usage to zero while it stays on dying_tasks. The attacker can retry until the reader lands on that task.\nPR:L - cgroup_file_mode() makes cgroup.procs S_IRUGO, so any unprivileged local user can read it. Creating and exiting threads in their own cgroup needs no capability, so a basic local account is enough.\nUI:N - The attacker triggers the race entirely with their own processes and their own reads of cgroup.procs. No other user or administrator has to do anything.\nS:U - The use-after-free corrupts a kernel task_struct within the same kernel security authority. It does not cross a VM, IOMMU or similar boundary.\nC:H - get_task_struct() on a zero-refcount task makes the iterator keep a task_struct that free_task() releases. cgroup_procs_show() then dereferences it via task_pid_vnr(), so a reclaimed object's contents are read and reported back to userspace.\nI:H - The iterator later calls put_task_struct() on the freed task_struct, decrementing ->usage in memory that may have been reallocated. This use-after-free write on reclaimed slab memory can be groomed into a corruption primitive.\nA:H - The refcount_t \"addition on 0\" warning, followed by dereferencing and releasing a freed task_struct in css_task_iter_next()/css_task_iter_end(), causes an oops, or a panic with panic_on_warn/KASAN, and an unprivileged user can repeat it."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["kernel/cgroup/cgroup.c"],"versions":[{"version":"260fbcb92bbeacfcd050410fdc2d24ab15044400","lessThan":"828938118d6c2bb711301748c3e39e4bed6a62f5","status":"affected","versionType":"git"},{"version":"260fbcb92bbeacfcd050410fdc2d24ab15044400","lessThan":"057dac23d329d5c5ed62352f2659a39fd46c6d4a","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["kernel/cgroup/cgroup.c"],"versions":[{"version":"6.19","status":"affected"},{"version":"0","lessThan":"6.19","status":"unaffected","versionType":"semver"},{"version":"7.2.8","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc4","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.19","versionEndExcluding":"7.2.8"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.19","versionEndExcluding":"7.3-rc4"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/828938118d6c2bb711301748c3e39e4bed6a62f5"},{"url":"https://git.kernel.org/stable/c/057dac23d329d5c5ed62352f2659a39fd46c6d4a"}],"title":"cgroup: Avoid iteration of dying tasks with zero refcount","x_generator":{"engine":"bippy-1.2.0"}}}}