locking/rt: Fix the incorrect RCU protection in rt_spin_unlock()
Published Aug 15, 2026
9.8
CRITICALCVSS 3.1
EPSS 0.73%
Description
rt_spin_unlock() releases the RCU protection before unlocking the lock. That opens the door for the following UAF scenario:
T1 T2 spin_lock(&p->lock); rcu_read_lock(); invalidate(p); p = rcu_dereference(ptr); rcu_assign_pointer(ptr, NULL); if (!p) return; spin_unlock(&p->lock); spin_lock(&p->lock) lock(&lock->lock); rcu_read_lock(); kfree_rcu(p); rcu_read_unlock(); .... spin_unlock(&p->lock) rcu_read_unlock(); // Ends grace period rcu_do_batch() kfree(p); UAF -> rt_mutex_cmpxchg_release(&lock->lock...)
Regular spinlocks keep preemption disabled accross the unlock operation, which provides full RCU protection, but the RT substitution fails to resemble that. Same applies for the rwlock substitution.
Move the rcu_read_unlock() invocation past the unlock operations to match the non-RT semantics. This makes it asymmetric vs. rt_xxx_lock(), but that's harmless as the caller needs to hold RCU read lock across the lock operation. The migrate_enable() call stays before the unlock operation because there is no per CPU operation in the unlock path which would require migration to be kept disabled.
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 5.15StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<5.15
- Version 5.15.217StatusunaffectedConstraints<=5.15.*
- Version 6.1.184StatusunaffectedConstraints<=6.1.*
- Version 6.12.101StatusunaffectedConstraints<=6.12.*
- Version 6.18.40StatusunaffectedConstraints<=6.18.*
- Version 6.6.148StatusunaffectedConstraints<=6.6.*
- Version 7.1.5StatusunaffectedConstraints<=7.1.*
- Version 7.2StatusunaffectedConstraints<=*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux | unaffected |
| ||||||||||||||||||||||||||||||
| Linux | Linux | affected |
|
No data.
No data.
Red Hat Enterprise Linux 10
kernel-0:6.12.0-211.50.1.el10_2
Fixed · RHSA-2026:61887
Red Hat Enterprise Linux 9
kernel-0:5.14.0-687.44.1.el9_8
Fixed · RHSA-2026:63129
Red Hat Enterprise Linux 9
kernel-0:5.14.0-687.44.1.el9_8
Fixed · RHSA-2026:63129
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | kernel-0:6.12.0-211.50.1.el10_2 | Fixed | RHSA-2026:61887 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-687.44.1.el9_8 | Fixed | RHSA-2026:63129 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-687.44.1.el9_8 | Fixed | RHSA-2026:63129 |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (13)
- https://access.redhat.com/security/cve/CVE-2026-72069 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2516248 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-59027 Advisory
- https://git.kernel.org/stable/c/1f0d56d3f1e88f20f6e46109402f8c15d59bac37
- https://git.kernel.org/stable/c/3cfaac77b3c32ac3940df28866de263c3f45d24c
- https://git.kernel.org/stable/c/633cadbc0b8323f5cc140a285d2432089dbb534e
- https://git.kernel.org/stable/c/83f9fb561c1c3917e19f95523dd933c7d30291aa
- https://git.kernel.org/stable/c/89038cc87d80c77e7aa6f42a64b2573b74af339f
- https://git.kernel.org/stable/c/9d1fcd64ab81200e02b7a6db5eb1da8e244e8289
- https://git.kernel.org/stable/c/af28d801cd2db4cc7378554499bd4a5d84a5517e
- https://lore.kernel.org/linux-cve-announce/2026081519-CVE-2026-72069-dde8@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2026-72069
- https://www.cve.org/CVERecord?id=CVE-2026-72069
Change history (0)
No recorded changes yet.