{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-98260","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-25T10:25:14.332Z","datePublished":"2026-10-06T08:45:24.711Z","dateUpdated":"2026-10-07T06:49:47.661Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-10-07T06:49:47.661Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nexec: Cleanup POSIX timers right after de_thread()\n\nA per-thread CPU timer holds a reference to the PID of the thread it is\nattached to and, while it is armed, its node is queued in that thread's\nposix_cputimers. The task is looked up by that PID.\n\nWhen a non-leader thread exec()s, de_thread() changes which task owns\nthat PID. pid_task(timer->it.cpu.pid, PIDTYPE_PID) then returns NULL,\nbut the node is still queued on tsk, which is alive. timer_lock_sighand()\ntakes a failed lookup to mean that the node is already dequeued, so it\nhas nothing to undo.\n\nbegin_new_exec() calls posix_cpu_timers_exit(me) right after\nexec_task_namespaces() and that removes the leftover node, so the state\nnormally stays invisible. But bprm->point_of_no_return is set before\nde_thread(), so if unshare_files(), set_mm_exe_file(), exec_mmap() or\nexec_task_namespaces() fails, the task dies before it gets there.\nexit_itimers() then frees the k_itimer while its node is still queued,\nand reaping tsk later erases that freed node from the rbtree.\n\nIn short:\n\n      the non-leader thread B           the parent\n\n  timer_create(CLOCK_THREAD_CPUTIME_ID)\n  timer_settime()\n    arm_timer()            // the node is queued on B\n  execve()\n    de_thread(B)\n      exchange_tids(B, leader)  // B's PID now belongs to the leader\n      release_task(leader)\n        __exit_signal(leader)\n          posix_cpu_timers_exit(leader)  // cleans leader's queue, not B's\n          __unhash_process(leader)  // that PID has no task anymore\n    exec_mmap()\n      mmap_read_lock_killable(old_mm)\n                                kill(B, SIGKILL)\n      // -EINTR\n  get_signal()\n    do_exit()\n      exit_itimers()\n        posix_timer_delete()\n          posix_cpu_timer_del()\n        posix_timer_unhash_and_free()  // freed while still queued\n                                wait4()\n                                  release_task(B)\n                                    posix_cpu_timers_exit(B)\n                                      cleanup_timerqueue()\n                                        timerqueue_del()  // use-after-free\n\nMove the POSIX timer cleanup right after de_thread() before any of the\nlater failure conditions brings the task into do_exit().\n\n[ tglx: Move the cleanup right after de_thread() ]"}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The bug needs local syscalls: timer_create(CLOCK_THREAD_CPUTIME_ID) and timer_settime() on a non-leader thread, then execve(). That thread's exec must fail after de_thread() in begin_new_exec() (e.g. exec_mmap() returning -EINTR on SIGKILL). No remote protocol carries any of this input.\nAC:L - The attacker controls both sides of the race. Their own parent sends SIGKILL while exec_mmap() waits on down_write_killable(exec_update_lock) or mmap_read_lock_killable(old_mm), and they can create that lock contention with their own CLONE_VM or /proc readers. No condition outside their control is needed.\nPR:L - Arming a thread CPU timer, calling execve and signalling one's own child are all available to any unprivileged user, with no capability checks on this path. A local unprivileged account is enough.\nUI:N - The attacker's own processes perform every step (timer arm, execve from a non-leader thread, SIGKILL, wait4 reap), so no victim action is needed.\nS:U - The memory corruption is inside the kernel that the attacker's process runs on. The outcome is a normal local privilege escalation, with no VM or sandbox boundary crossed.\nC:H - exit_itimers() frees the k_itimer while its cpu_timer node is still linked in the task's posix_cputimers rbtree. The freed slab object can be reclaimed with attacker-sprayed data, giving a use-after-free that can be turned into kernel memory disclosure.\nI:H - When release_task() reaps the task, posix_cpu_timers_exit() -> cleanup_timerqueue() -> timerqueue_del() calls rb_erase on the freed node and rewrites rbtree pointers in reclaimed memory. That is a use-after-free write which can be used for privilege escalation.\nA:H - The rbtree erase on freed memory corrupts kernel data and can oops or panic the kernel. Any unprivileged user can repeat it at will."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/exec.c"],"versions":[{"version":"55e8c8eb2c7b6bf30e99423ccfe7ca032f498f59","lessThan":"6f1977cea3e85cd8ab55fb337d3e1725fe61d1ce","status":"affected","versionType":"git"},{"version":"55e8c8eb2c7b6bf30e99423ccfe7ca032f498f59","lessThan":"d9ae467e617ca29b825493a362bf0d75ad5f4ac3","status":"affected","versionType":"git"},{"version":"55e8c8eb2c7b6bf30e99423ccfe7ca032f498f59","lessThan":"75aa08b93c65766040f9ca99f41ac85ad22596b6","status":"affected","versionType":"git"},{"version":"55e8c8eb2c7b6bf30e99423ccfe7ca032f498f59","lessThan":"d602877baf36c43c788a5f472c977e0be414029f","status":"affected","versionType":"git"},{"version":"55e8c8eb2c7b6bf30e99423ccfe7ca032f498f59","lessThan":"acb03d3881818581052924a9bbbe92b8741ed448","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/exec.c"],"versions":[{"version":"5.7","status":"affected"},{"version":"0","lessThan":"5.7","status":"unaffected","versionType":"semver"},{"version":"6.6.158","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.112","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.54","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.8","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc4","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.7","versionEndExcluding":"6.6.158"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.7","versionEndExcluding":"6.12.112"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.7","versionEndExcluding":"6.18.54"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.7","versionEndExcluding":"7.2.8"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.7","versionEndExcluding":"7.3-rc4"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/6f1977cea3e85cd8ab55fb337d3e1725fe61d1ce"},{"url":"https://git.kernel.org/stable/c/d9ae467e617ca29b825493a362bf0d75ad5f4ac3"},{"url":"https://git.kernel.org/stable/c/75aa08b93c65766040f9ca99f41ac85ad22596b6"},{"url":"https://git.kernel.org/stable/c/d602877baf36c43c788a5f472c977e0be414029f"},{"url":"https://git.kernel.org/stable/c/acb03d3881818581052924a9bbbe92b8741ed448"}],"title":"exec: Cleanup POSIX timers right after de_thread()","x_generator":{"engine":"bippy-1.2.0"}}}}