PT-2026-98557 · Linux · Linux

CVE-2026-97617

·

Published

2026-09-25

·

Updated

2026-09-25

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
ring-buffer: Check resize disabled before publishing the new subbuf order
ring buffer subbuf order set() stores the new order and only then walks the CPUs, returning -EBUSY if any of them has resizing disabled. A user mapped buffer has resizing disabled, and rb map vma() reads buffer->subbuf order without buffer->mutex, so an mmap of an already mapped CPU racing the failing order change sizes the mapping with the new order and inserts pages past the sub-buffer into the VMA.
Check the CPUs before storing the new order.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-97617

Affected Products

Linux