PT-2026-93644 · Linux · Linux Kernel

CVE-2026-90003

·

Published

2026-09-16

·

Updated

2026-09-24

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description On PREEMPT RT, a use-after-free issue exists during a Priority Inheritance (PI) requeue. The problem occurs when FUTEX CMP REQUEUE PI triggers a slab-out-of-bounds report in the futex requeue pi complete() function during the invocation of rcuwait wake up(). This happens because the futex q used by futex wait requeue pi() is allocated on the waiter's stack. A race condition occurs when an early wakeup allows the waiter to leave the system call before the requeue task completes the wake operation, leading to a situation where rcuwait wake up() is called after the memory has been reclaimed.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-101435
CVE-2026-90003
OPENSUSE-SU-2026:11880-1

Affected Products

Linux Kernel