rtmutex: Use waiter::task instead of current in remove_waiter()
Published May 21, 2026
7.8
HIGHCVSS 3.1
EPSS 0.28%
Description
remove_waiter() is used by the slowlock paths, but it is also used for proxy-lock rollback in rt_mutex_start_proxy_lock() when invoked from futex_requeue().
In the latter case waiter::task is not current, but remove_waiter() operates on current for the dequeue operation. That results in several problems:
1) the rbtree dequeue happens without waiter::task::pi_lock being held
2) the waiter task's pi_blocked_on state is not cleared, which leaves a dangling pointer primed for UAF around.
3) rt_mutex_adjust_prio_chain() operates on the wrong top priority waiter task
Use waiter::task instead of current in all related operations in remove_waiter() to cure those problems.
[ tglx: Fixup rt_mutex_adjust_prio_chain(), add a comment and amend the changelog ]
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 2.6.39StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<2.6.39
- Version 5.10.261StatusunaffectedConstraints<=5.10.*
- Version 5.15.212StatusunaffectedConstraints<=5.15.*
- Version 6.1.175StatusunaffectedConstraints<=6.1.*
- Version 6.12.86StatusunaffectedConstraints<=6.12.*
- Version 6.18.27StatusunaffectedConstraints<=6.18.*
- Version 6.6.140StatusunaffectedConstraints<=6.6.*
- Version 7.0.4StatusunaffectedConstraints<=7.0.*
- Version 7.1StatusunaffectedConstraints<=*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux | unaffected |
| |||||||||||||||||||||||||||||||||
| Linux | Linux | affected |
|
- ≥ 2.6.39 · < 6.1.175
- ≥ 6.2 · < 6.6.140
- ≥ 6.7 · < 6.12.86
- ≥ 6.13 · < 6.18.27
- ≥ 6.19 · < 7.0.4
No data.
NVIDIA for RHEL 10
kernel-0:6.12.0-231.16.el10nv
Fixed · RHSA-2026:37728
Red Hat Enterprise Linux 10
kernel-0:6.12.0-211.33.1.el10_2
Fixed · RHSA-2026:38492
Red Hat Enterprise Linux 10
kpatch-patch
Fixed · RHSA-2026:59143
Red Hat Enterprise Linux 10.0 Extended Update Support
kernel-0:6.12.0-55.89.1.el10_0
Fixed · RHSA-2026:41062
Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSION
kernel-0:2.6.32-754.62.1.el6
Fixed · RHSA-2026:41920
Red Hat Enterprise Linux 7 Extended Lifecycle Support
kernel-0:3.10.0-1160.156.1.el7
Fixed · RHSA-2026:41235
Red Hat Enterprise Linux 7 Extended Lifecycle Support
kernel-rt-0:3.10.0-1160.156.1.rt56.1308.el7
Fixed · RHSA-2026:41234
Red Hat Enterprise Linux 8
kernel-0:4.18.0-553.143.1.el8_10
Fixed · RHSA-2026:39083
Red Hat Enterprise Linux 8
kernel-rt-0:4.18.0-553.143.1.rt7.484.el8_10
Fixed · RHSA-2026:39082
Red Hat Enterprise Linux 8
kpatch-patch
Fixed · RHSA-2026:59146
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
kernel-0:4.18.0-305.198.1.el8_4
Fixed · RHSA-2026:39984
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On
kernel-0:4.18.0-305.198.1.el8_4
Fixed · RHSA-2026:39984
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
kernel-0:4.18.0-372.201.1.el8_6
Fixed · RHSA-2026:40068
Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On
kernel-0:4.18.0-372.201.1.el8_6
Fixed · RHSA-2026:40068
Red Hat Enterprise Linux 8.8 Telecommunications Update Service
kernel-0:4.18.0-477.152.1.el8_8
Fixed · RHSA-2026:40760
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
kernel-0:4.18.0-477.152.1.el8_8
Fixed · RHSA-2026:40760
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
kpatch-patch
Fixed · RHSA-2026:59142
Red Hat Enterprise Linux 9
kernel-0:5.14.0-687.25.1.el9_8
Fixed · RHSA-2026:38491
Red Hat Enterprise Linux 9
kernel-0:5.14.0-687.25.1.el9_8
Fixed · RHSA-2026:38491
Red Hat Enterprise Linux 9
kpatch-patch
Fixed · RHSA-2026:59149
Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions
kernel-0:5.14.0-284.181.1.el9_2
Fixed · RHSA-2026:40082
Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions
kernel-rt-0:5.14.0-284.181.1.rt14.466.el9_2
Fixed · RHSA-2026:39983
Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions
kpatch-patch
Fixed · RHSA-2026:59147
Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions
kernel-0:5.14.0-427.138.1.el9_4
Fixed · RHSA-2026:41063
Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions
kpatch-patch
Fixed · RHSA-2026:59145
Red Hat Enterprise Linux 9.6 Extended Update Support
kernel-0:5.14.0-570.128.1.el9_6
Fixed · RHSA-2026:40425
Red Hat Enterprise Linux 9.6 Extended Update Support
kpatch-patch
Fixed · RHSA-2026:59148
Red Hat Enterprise Linux 9
kernel-rt
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| NVIDIA for RHEL 10 | kernel-0:6.12.0-231.16.el10nv | Fixed | RHSA-2026:37728 |
| Red Hat Enterprise Linux 10 | kernel-0:6.12.0-211.33.1.el10_2 | Fixed | RHSA-2026:38492 |
| Red Hat Enterprise Linux 10 | kpatch-patch | Fixed | RHSA-2026:59143 |
| Red Hat Enterprise Linux 10.0 Extended Update Support | kernel-0:6.12.0-55.89.1.el10_0 | Fixed | RHSA-2026:41062 |
| Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSION | kernel-0:2.6.32-754.62.1.el6 | Fixed | RHSA-2026:41920 |
| Red Hat Enterprise Linux 7 Extended Lifecycle Support | kernel-0:3.10.0-1160.156.1.el7 | Fixed | RHSA-2026:41235 |
| Red Hat Enterprise Linux 7 Extended Lifecycle Support | kernel-rt-0:3.10.0-1160.156.1.rt56.1308.el7 | Fixed | RHSA-2026:41234 |
| Red Hat Enterprise Linux 8 | kernel-0:4.18.0-553.143.1.el8_10 | Fixed | RHSA-2026:39083 |
| Red Hat Enterprise Linux 8 | kernel-rt-0:4.18.0-553.143.1.rt7.484.el8_10 | Fixed | RHSA-2026:39082 |
| Red Hat Enterprise Linux 8 | kpatch-patch | Fixed | RHSA-2026:59146 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | kernel-0:4.18.0-305.198.1.el8_4 | Fixed | RHSA-2026:39984 |
| Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | kernel-0:4.18.0-305.198.1.el8_4 | Fixed | RHSA-2026:39984 |
| Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | kernel-0:4.18.0-372.201.1.el8_6 | Fixed | RHSA-2026:40068 |
| Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On | kernel-0:4.18.0-372.201.1.el8_6 | Fixed | RHSA-2026:40068 |
| Red Hat Enterprise Linux 8.8 Telecommunications Update Service | kernel-0:4.18.0-477.152.1.el8_8 | Fixed | RHSA-2026:40760 |
| Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | kernel-0:4.18.0-477.152.1.el8_8 | Fixed | RHSA-2026:40760 |
| Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | kpatch-patch | Fixed | RHSA-2026:59142 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-687.25.1.el9_8 | Fixed | RHSA-2026:38491 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-687.25.1.el9_8 | Fixed | RHSA-2026:38491 |
| Red Hat Enterprise Linux 9 | kpatch-patch | Fixed | RHSA-2026:59149 |
| Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | kernel-0:5.14.0-284.181.1.el9_2 | Fixed | RHSA-2026:40082 |
| Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | kernel-rt-0:5.14.0-284.181.1.rt14.466.el9_2 | Fixed | RHSA-2026:39983 |
| Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | kpatch-patch | Fixed | RHSA-2026:59147 |
| Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions | kernel-0:5.14.0-427.138.1.el9_4 | Fixed | RHSA-2026:41063 |
| Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions | kpatch-patch | Fixed | RHSA-2026:59145 |
| Red Hat Enterprise Linux 9.6 Extended Update Support | kernel-0:5.14.0-570.128.1.el9_6 | Fixed | RHSA-2026:40425 |
| Red Hat Enterprise Linux 9.6 Extended Update Support | kpatch-patch | Fixed | RHSA-2026:59148 |
| Red Hat Enterprise Linux 9 | kernel-rt | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
See the security bulletin for a detailed mitigation procedure.
References (16)
- http://www.openwall.com/lists/oss-security/2026/07/08/12
- https://access.redhat.com/security/cve/CVE-2026-43499 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2480453 Issue Tracking
- https://cert-portal.siemens.com/productcert/html/ssa-019113.html
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-31277 Advisory
- https://git.kernel.org/stable/c/3bfdc63936dd4773109b7b8c280c0f3b5ae7d349 Patch
- https://git.kernel.org/stable/c/3fb7394a837740770f0d6b4b30567e60786a63f2 Patch
- https://git.kernel.org/stable/c/6d52dfcb2a5db86e346cf51f8fcf2071b8085166 Patch
- https://git.kernel.org/stable/c/838ce5cb5d93c3ab8b27e75bc6ad905a94b752fd
- https://git.kernel.org/stable/c/88614876370aac8ad1050ad785a4c095ba17ac11 Patch
- https://git.kernel.org/stable/c/8a1fc8d698ac5e5916e3082a0f74450d71f9611f Patch
- https://git.kernel.org/stable/c/d8cce4773c2b23d819baf5abedc62f7b430e8745 Patch
- https://git.kernel.org/stable/c/f3fa3424bceb128d2be4b3745506b22844b87db7
- https://lore.kernel.org/linux-cve-announce/2026052158-CVE-2026-43499-1294@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2026-43499
- https://www.cve.org/CVERecord?id=CVE-2026-43499
Change history (0)
No recorded changes yet.