Race condition in Linux kernel - CVE-2026-52977
Published: June 25, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a race condition in futex requeue-PI handling in kernel/futex/requeue.c when processing wait-requeue-pi and requeue-PI operations during signal or timeout wakeup. A local user can trigger concurrent futex operations to cause a denial of service.
The issue can result in a live lock where one task blocks on a hash bucket lock while another busy loops, potentially locking up the system.
How to mitigate CVE-2026-52977
Sources
- https://git.kernel.org/stable/c/0304d60abb9dcc02bc7fe6d1850f4ca206e8f1a0
- https://git.kernel.org/stable/c/0aacb6d18f76552e3e0ee25d9f40d21b3486f4cf
- https://git.kernel.org/stable/c/4e0ed44e51727d56244a822ab941efe507c47966
- https://git.kernel.org/stable/c/69a7cfc66405aeaa2483147653d031b3592ffc9c
- https://git.kernel.org/stable/c/bc7304f3ae20972d11db6e0b1b541c63feda5f05
- https://git.kernel.org/stable/c/e3f95b1ba242e37093305812df7fdbe7288a43ac