kernel: cgroup: Avoid iteration of dying tasks with zero refcount
cve CVE-2026-98163 3 sources, 4 claims · Watch
What it is to other things
| affects | linux/linux_kernel NVD |
| made_by | linux NVD |
In words only, so not counted until a person confirms one:
| affects | linux/linuxNVD says “Linux · Linux” |
What each source says
| Property | Source | Said | Means here | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Cvss cvss conflict | NVD | 7receipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"kernel/cgroup/cgroup.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "828938118d6c2bb711301748c3e39e4bed6a62f5",
"status": "affected",
"version": "260fbcb92bbeacfcd050410fdc2d24ab15044400",
"versionType": "git"
},
{
"lessThan": "057dac23d329d5c5ed62352f2659a39fd46c6d4a",
"status": "affected",
"version": "260fbcb92bbeacfcd050410fdc2d24ab15044400",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"kernel/cgroup/cgroup.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.19"
},
{
"lessThan": "6.19",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.2.*",
"status": "unaffected",
"version": "7.2.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.3-rc4",
"versionType": "original_commit_for_fix"
}
]
}
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"matchCriteriaId": "03F96438-F355-42FE-99A2-E7C298C7580F",
"versionEndExcluding": "7.2.8",
"versionStartIncluding": "6.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:7.3:rc1:*:*:*:*:*:*",
"matchCriteriaId": "11E35E1B-5DB4-4AB9-9706-CD73B799EADF",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:7.3:rc2:*:*:*:*:*:*",
"matchCriteriaId": "14FD7B9A-4946-4511-8E63-6E13870CD4A8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:7.3:rc3:*:*:*:*:*:*",
"matchCriteriaId": "F06EDE17-AD0F-4C81-AF8C-D86B6AF0F622",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncgroup: Avoid iteration of dying tasks with zero refcount\n\nThe commit 260fbcb92bbea (\"cgroup: Move dying_tasks cleanup from\ncgroup_task_release() to cgroup_task_free()\") extended the lifetime of\ntasks on the dying_tasks list.\nThe iterators have provision to go through dying_tasks because of\ndying threadgroup leaders or explicit CSS_TASK_ITER_WITH_DEAD, however,\nit was expected that such tasks can obtain a new reference (that is\npossible before cgroup_task_release()/put_task_struct_rcu_user()).\nThe tasks after cgroup_task_release() and before cgroup_task_free()\nare subject to race when they may or may not have ->usage count > 0.\n\nThe race window is between css_task_iter_next() invocations\nwhen css_set_lock is released and we may arrive at a new ->task_pos.\nThe iterator should not attempt to resurrect tasks whose ->usage count\ndropped to zero. (When that happens, __put_task_struct_rcu_cb() is\nalready imminent and the returned task_struct would could be used\nafter free.)\n\nAs for the fix, we cannot simply check the signal->live count of a task\non the dying list because that won't distinguish regular zombies waiting\nto be reaped from RCU remnant tasks that are going to be free'd.\nTherefore add an extra check to rule out ->usage==0 tasks from any\niteration.\n\nThe repeat: loop in css_task_iter_advance() doesn't consider ->usage\ncount, so add a new loop to css_task_iter_next() to skip de-used tasks\non the dying_list.\n\nRough illustration of the possible race\n\n R (reader of cgroup.procs) T (thread) L (group leader)\n --------------------------------- -------------------------------- --------------------------------\n L exits, signal->live > 0\n cgroup_task_dead(L)\n css_set_skip_task_iters() // skips only cset->tasks\n list_add_tail(&L->cg_list, &cset->dying_tasks)\n css_task_iter_next()\n take css_set_lock\n css_task_iter_advance()\n leader && signal->live != 0\n => it->task_pos = &L->cg_list\n release css_set_lock\n T exits\n --signal->live == 0\n\t\t\t\t cgroup_task_dead(T) // css_set_lock\n release_task(T)\n cgroup_task_release(T)\n release_task(L) // zap_leader\n cgroup_task_release(L)\n put_task_struct_rcu_user(L)\n ...RCU...\n put_task_struct(L)\n L->usage = 0\n /* L still on dying_tasks */\n ...RCU...\n __put_task_struct(L)\n css_task_iter_next() // another iteration\n take css_set_lock\n it->task_pos = &L->cg_list\n get_task_struct(L)\n => addition on 0\n drop css_set_lock\n cgroup_task_free(L)\n css_set_skip_task_iters() // dying skip comes too late\n free_task(L)\n cgroup_procs_show()\n task_pid_vnr(L)"
}
],
"id": "CVE-2026-98163",
"lastModified": "2026-10-02T20:55:39.043",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "HIGH",
"attackVector": "LOCAL",
"availabilityImpact": "HIGH",
"baseScore": 7.0,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"exploitabilityScore": 1.0,
"impactScore": 5.9,
"source": "nvd@nist.gov",
"type": "Primary"
}
]
},
"published": "2026-09-26T09:16:38.303",
"references": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"tags": [
"Patch"
],
"url": "https://git.kernel.org/stable/c/057dac23d329d5c5ed62352f2659a39fd46c6d4a"
},
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"tags": [
"Patch"
],
"url": "https://git.kernel.org/stable/c/828938118d6c2bb711301748c3e39e4bed6a62f5"
}
],
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-362"
},
{
"lang": "en",
"value": "CWE-416"
}
],
"source": "nvd@nist.gov",
"type": "Primary"
}
]
}
} | — | ||||||
| Cvss cvss conflict | Red Hat | 5.5receipt
What the source handed over{
"CVE": "CVE-2026-98163",
"CWE": "CWE-366",
"advisories": [],
"affected_packages": [],
"bugzilla": "2541788",
"bugzilla_description": "kernel: cgroup: Avoid iteration of dying tasks with zero refcount",
"cvss3_score": "5.5",
"cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"cvss_score": null,
"cvss_scoring_vector": null,
"package_state": null,
"public_date": "2026-09-26T00:00:00Z",
"resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-98163.json",
"severity": "moderate"
} | — | ||||||
| Cwe cwe | Red Hat | CWE-366receipt
What the source handed over{
"CVE": "CVE-2026-98163",
"CWE": "CWE-366",
"advisories": [],
"affected_packages": [],
"bugzilla": "2541788",
"bugzilla_description": "kernel: cgroup: Avoid iteration of dying tasks with zero refcount",
"cvss3_score": "5.5",
"cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"cvss_score": null,
"cvss_scoring_vector": null,
"package_state": null,
"public_date": "2026-09-26T00:00:00Z",
"resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-98163.json",
"severity": "moderate"
} | — | ||||||
| Product product | NVD | Linuxreceipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"kernel/cgroup/cgroup.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "828938118d6c2bb711301748c3e39e4bed6a62f5",
"status": "affected",
"version": "260fbcb92bbeacfcd050410fdc2d24ab15044400",
"versionType": "git"
},
{
"lessThan": "057dac23d329d5c5ed62352f2659a39fd46c6d4a",
"status": "affected",
"version": "260fbcb92bbeacfcd050410fdc2d24ab15044400",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"kernel/cgroup/cgroup.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.19"
},
{
"lessThan": "6.19",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.2.*",
"status": "unaffected",
"version": "7.2.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.3-rc4",
"versionType": "original_commit_for_fix"
}
]
}
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"matchCriteriaId": "03F96438-F355-42FE-99A2-E7C298C7580F",
"versionEndExcluding": "7.2.8",
"versionStartIncluding": "6.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:7.3:rc1:*:*:*:*:*:*",
"matchCriteriaId": "11E35E1B-5DB4-4AB9-9706-CD73B799EADF",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:7.3:rc2:*:*:*:*:*:*",
"matchCriteriaId": "14FD7B9A-4946-4511-8E63-6E13870CD4A8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:7.3:rc3:*:*:*:*:*:*",
"matchCriteriaId": "F06EDE17-AD0F-4C81-AF8C-D86B6AF0F622",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncgroup: Avoid iteration of dying tasks with zero refcount\n\nThe commit 260fbcb92bbea (\"cgroup: Move dying_tasks cleanup from\ncgroup_task_release() to cgroup_task_free()\") extended the lifetime of\ntasks on the dying_tasks list.\nThe iterators have provision to go through dying_tasks because of\ndying threadgroup leaders or explicit CSS_TASK_ITER_WITH_DEAD, however,\nit was expected that such tasks can obtain a new reference (that is\npossible before cgroup_task_release()/put_task_struct_rcu_user()).\nThe tasks after cgroup_task_release() and before cgroup_task_free()\nare subject to race when they may or may not have ->usage count > 0.\n\nThe race window is between css_task_iter_next() invocations\nwhen css_set_lock is released and we may arrive at a new ->task_pos.\nThe iterator should not attempt to resurrect tasks whose ->usage count\ndropped to zero. (When that happens, __put_task_struct_rcu_cb() is\nalready imminent and the returned task_struct would could be used\nafter free.)\n\nAs for the fix, we cannot simply check the signal->live count of a task\non the dying list because that won't distinguish regular zombies waiting\nto be reaped from RCU remnant tasks that are going to be free'd.\nTherefore add an extra check to rule out ->usage==0 tasks from any\niteration.\n\nThe repeat: loop in css_task_iter_advance() doesn't consider ->usage\ncount, so add a new loop to css_task_iter_next() to skip de-used tasks\non the dying_list.\n\nRough illustration of the possible race\n\n R (reader of cgroup.procs) T (thread) L (group leader)\n --------------------------------- -------------------------------- --------------------------------\n L exits, signal->live > 0\n cgroup_task_dead(L)\n css_set_skip_task_iters() // skips only cset->tasks\n list_add_tail(&L->cg_list, &cset->dying_tasks)\n css_task_iter_next()\n take css_set_lock\n css_task_iter_advance()\n leader && signal->live != 0\n => it->task_pos = &L->cg_list\n release css_set_lock\n T exits\n --signal->live == 0\n\t\t\t\t cgroup_task_dead(T) // css_set_lock\n release_task(T)\n cgroup_task_release(T)\n release_task(L) // zap_leader\n cgroup_task_release(L)\n put_task_struct_rcu_user(L)\n ...RCU...\n put_task_struct(L)\n L->usage = 0\n /* L still on dying_tasks */\n ...RCU...\n __put_task_struct(L)\n css_task_iter_next() // another iteration\n take css_set_lock\n it->task_pos = &L->cg_list\n get_task_struct(L)\n => addition on 0\n drop css_set_lock\n cgroup_task_free(L)\n css_set_skip_task_iters() // dying skip comes too late\n free_task(L)\n cgroup_procs_show()\n task_pid_vnr(L)"
}
],
"id": "CVE-2026-98163",
"lastModified": "2026-10-02T20:55:39.043",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "HIGH",
"attackVector": "LOCAL",
"availabilityImpact": "HIGH",
"baseScore": 7.0,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"exploitabilityScore": 1.0,
"impactScore": 5.9,
"source": "nvd@nist.gov",
"type": "Primary"
}
]
},
"published": "2026-09-26T09:16:38.303",
"references": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"tags": [
"Patch"
],
"url": "https://git.kernel.org/stable/c/057dac23d329d5c5ed62352f2659a39fd46c6d4a"
},
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"tags": [
"Patch"
],
"url": "https://git.kernel.org/stable/c/828938118d6c2bb711301748c3e39e4bed6a62f5"
}
],
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-362"
},
{
"lang": "en",
"value": "CWE-416"
}
],
"source": "nvd@nist.gov",
"type": "Primary"
}
]
}
} | — | ||||||
| Severity severity conflict | GitHub advisories | unknownreceipt
This source has not kept a receipt for this claim yet. The next update that reads it will. | — | ||||||
| Severity severity conflict | Red Hat | moderate A flaw that is harder to exploit, or whose impact is limited. receipt
What the source handed over{
"CVE": "CVE-2026-98163",
"CWE": "CWE-366",
"advisories": [],
"affected_packages": [],
"bugzilla": "2541788",
"bugzilla_description": "kernel: cgroup: Avoid iteration of dying tasks with zero refcount",
"cvss3_score": "5.5",
"cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"cvss_score": null,
"cvss_scoring_vector": null,
"package_state": null,
"public_date": "2026-09-26T00:00:00Z",
"resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-98163.json",
"severity": "moderate"
} | medium | ||||||
| Status status | NVD | Analyzedreceipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"kernel/cgroup/cgroup.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "828938118d6c2bb711301748c3e39e4bed6a62f5",
"status": "affected",
"version": "260fbcb92bbeacfcd050410fdc2d24ab15044400",
"versionType": "git"
},
{
"lessThan": "057dac23d329d5c5ed62352f2659a39fd46c6d4a",
"status": "affected",
"version": "260fbcb92bbeacfcd050410fdc2d24ab15044400",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"kernel/cgroup/cgroup.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.19"
},
{
"lessThan": "6.19",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.2.*",
"status": "unaffected",
"version": "7.2.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.3-rc4",
"versionType": "original_commit_for_fix"
}
]
}
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"matchCriteriaId": "03F96438-F355-42FE-99A2-E7C298C7580F",
"versionEndExcluding": "7.2.8",
"versionStartIncluding": "6.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:7.3:rc1:*:*:*:*:*:*",
"matchCriteriaId": "11E35E1B-5DB4-4AB9-9706-CD73B799EADF",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:7.3:rc2:*:*:*:*:*:*",
"matchCriteriaId": "14FD7B9A-4946-4511-8E63-6E13870CD4A8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:7.3:rc3:*:*:*:*:*:*",
"matchCriteriaId": "F06EDE17-AD0F-4C81-AF8C-D86B6AF0F622",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncgroup: Avoid iteration of dying tasks with zero refcount\n\nThe commit 260fbcb92bbea (\"cgroup: Move dying_tasks cleanup from\ncgroup_task_release() to cgroup_task_free()\") extended the lifetime of\ntasks on the dying_tasks list.\nThe iterators have provision to go through dying_tasks because of\ndying threadgroup leaders or explicit CSS_TASK_ITER_WITH_DEAD, however,\nit was expected that such tasks can obtain a new reference (that is\npossible before cgroup_task_release()/put_task_struct_rcu_user()).\nThe tasks after cgroup_task_release() and before cgroup_task_free()\nare subject to race when they may or may not have ->usage count > 0.\n\nThe race window is between css_task_iter_next() invocations\nwhen css_set_lock is released and we may arrive at a new ->task_pos.\nThe iterator should not attempt to resurrect tasks whose ->usage count\ndropped to zero. (When that happens, __put_task_struct_rcu_cb() is\nalready imminent and the returned task_struct would could be used\nafter free.)\n\nAs for the fix, we cannot simply check the signal->live count of a task\non the dying list because that won't distinguish regular zombies waiting\nto be reaped from RCU remnant tasks that are going to be free'd.\nTherefore add an extra check to rule out ->usage==0 tasks from any\niteration.\n\nThe repeat: loop in css_task_iter_advance() doesn't consider ->usage\ncount, so add a new loop to css_task_iter_next() to skip de-used tasks\non the dying_list.\n\nRough illustration of the possible race\n\n R (reader of cgroup.procs) T (thread) L (group leader)\n --------------------------------- -------------------------------- --------------------------------\n L exits, signal->live > 0\n cgroup_task_dead(L)\n css_set_skip_task_iters() // skips only cset->tasks\n list_add_tail(&L->cg_list, &cset->dying_tasks)\n css_task_iter_next()\n take css_set_lock\n css_task_iter_advance()\n leader && signal->live != 0\n => it->task_pos = &L->cg_list\n release css_set_lock\n T exits\n --signal->live == 0\n\t\t\t\t cgroup_task_dead(T) // css_set_lock\n release_task(T)\n cgroup_task_release(T)\n release_task(L) // zap_leader\n cgroup_task_release(L)\n put_task_struct_rcu_user(L)\n ...RCU...\n put_task_struct(L)\n L->usage = 0\n /* L still on dying_tasks */\n ...RCU...\n __put_task_struct(L)\n css_task_iter_next() // another iteration\n take css_set_lock\n it->task_pos = &L->cg_list\n get_task_struct(L)\n => addition on 0\n drop css_set_lock\n cgroup_task_free(L)\n css_set_skip_task_iters() // dying skip comes too late\n free_task(L)\n cgroup_procs_show()\n task_pid_vnr(L)"
}
],
"id": "CVE-2026-98163",
"lastModified": "2026-10-02T20:55:39.043",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "HIGH",
"attackVector": "LOCAL",
"availabilityImpact": "HIGH",
"baseScore": 7.0,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"exploitabilityScore": 1.0,
"impactScore": 5.9,
"source": "nvd@nist.gov",
"type": "Primary"
}
]
},
"published": "2026-09-26T09:16:38.303",
"references": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"tags": [
"Patch"
],
"url": "https://git.kernel.org/stable/c/057dac23d329d5c5ed62352f2659a39fd46c6d4a"
},
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"tags": [
"Patch"
],
"url": "https://git.kernel.org/stable/c/828938118d6c2bb711301748c3e39e4bed6a62f5"
}
],
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-362"
},
{
"lang": "en",
"value": "CWE-416"
}
],
"source": "nvd@nist.gov",
"type": "Primary"
}
]
}
} | — | ||||||
| Vendor vendor | NVD | Linuxreceipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"kernel/cgroup/cgroup.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "828938118d6c2bb711301748c3e39e4bed6a62f5",
"status": "affected",
"version": "260fbcb92bbeacfcd050410fdc2d24ab15044400",
"versionType": "git"
},
{
"lessThan": "057dac23d329d5c5ed62352f2659a39fd46c6d4a",
"status": "affected",
"version": "260fbcb92bbeacfcd050410fdc2d24ab15044400",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"kernel/cgroup/cgroup.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.19"
},
{
"lessThan": "6.19",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.2.*",
"status": "unaffected",
"version": "7.2.8",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.3-rc4",
"versionType": "original_commit_for_fix"
}
]
}
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"matchCriteriaId": "03F96438-F355-42FE-99A2-E7C298C7580F",
"versionEndExcluding": "7.2.8",
"versionStartIncluding": "6.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:7.3:rc1:*:*:*:*:*:*",
"matchCriteriaId": "11E35E1B-5DB4-4AB9-9706-CD73B799EADF",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:7.3:rc2:*:*:*:*:*:*",
"matchCriteriaId": "14FD7B9A-4946-4511-8E63-6E13870CD4A8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:7.3:rc3:*:*:*:*:*:*",
"matchCriteriaId": "F06EDE17-AD0F-4C81-AF8C-D86B6AF0F622",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncgroup: Avoid iteration of dying tasks with zero refcount\n\nThe commit 260fbcb92bbea (\"cgroup: Move dying_tasks cleanup from\ncgroup_task_release() to cgroup_task_free()\") extended the lifetime of\ntasks on the dying_tasks list.\nThe iterators have provision to go through dying_tasks because of\ndying threadgroup leaders or explicit CSS_TASK_ITER_WITH_DEAD, however,\nit was expected that such tasks can obtain a new reference (that is\npossible before cgroup_task_release()/put_task_struct_rcu_user()).\nThe tasks after cgroup_task_release() and before cgroup_task_free()\nare subject to race when they may or may not have ->usage count > 0.\n\nThe race window is between css_task_iter_next() invocations\nwhen css_set_lock is released and we may arrive at a new ->task_pos.\nThe iterator should not attempt to resurrect tasks whose ->usage count\ndropped to zero. (When that happens, __put_task_struct_rcu_cb() is\nalready imminent and the returned task_struct would could be used\nafter free.)\n\nAs for the fix, we cannot simply check the signal->live count of a task\non the dying list because that won't distinguish regular zombies waiting\nto be reaped from RCU remnant tasks that are going to be free'd.\nTherefore add an extra check to rule out ->usage==0 tasks from any\niteration.\n\nThe repeat: loop in css_task_iter_advance() doesn't consider ->usage\ncount, so add a new loop to css_task_iter_next() to skip de-used tasks\non the dying_list.\n\nRough illustration of the possible race\n\n R (reader of cgroup.procs) T (thread) L (group leader)\n --------------------------------- -------------------------------- --------------------------------\n L exits, signal->live > 0\n cgroup_task_dead(L)\n css_set_skip_task_iters() // skips only cset->tasks\n list_add_tail(&L->cg_list, &cset->dying_tasks)\n css_task_iter_next()\n take css_set_lock\n css_task_iter_advance()\n leader && signal->live != 0\n => it->task_pos = &L->cg_list\n release css_set_lock\n T exits\n --signal->live == 0\n\t\t\t\t cgroup_task_dead(T) // css_set_lock\n release_task(T)\n cgroup_task_release(T)\n release_task(L) // zap_leader\n cgroup_task_release(L)\n put_task_struct_rcu_user(L)\n ...RCU...\n put_task_struct(L)\n L->usage = 0\n /* L still on dying_tasks */\n ...RCU...\n __put_task_struct(L)\n css_task_iter_next() // another iteration\n take css_set_lock\n it->task_pos = &L->cg_list\n get_task_struct(L)\n => addition on 0\n drop css_set_lock\n cgroup_task_free(L)\n css_set_skip_task_iters() // dying skip comes too late\n free_task(L)\n cgroup_procs_show()\n task_pid_vnr(L)"
}
],
"id": "CVE-2026-98163",
"lastModified": "2026-10-02T20:55:39.043",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "HIGH",
"attackVector": "LOCAL",
"availabilityImpact": "HIGH",
"baseScore": 7.0,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"exploitabilityScore": 1.0,
"impactScore": 5.9,
"source": "nvd@nist.gov",
"type": "Primary"
}
]
},
"published": "2026-09-26T09:16:38.303",
"references": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"tags": [
"Patch"
],
"url": "https://git.kernel.org/stable/c/057dac23d329d5c5ed62352f2659a39fd46c6d4a"
},
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"tags": [
"Patch"
],
"url": "https://git.kernel.org/stable/c/828938118d6c2bb711301748c3e39e4bed6a62f5"
}
],
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-362"
},
{
"lang": "en",
"value": "CWE-416"
}
],
"source": "nvd@nist.gov",
"type": "Primary"
}
]
}
} | — |