Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4353 articles · 196293 vulns · 36/41 feeds (7d)
← Back to list
7.8
CVE-2026-43499EXPLOITEDPATCHED
linux · linux_kernel

rtmutex: Use waiter::task instead of current in remove_waiter()

Description

In the Linux kernel, the following vulnerability has been resolved: rtmutex: Use waiter::task instead of current in remove_waiter() remove_waiter() is used by the slowlock paths, but it is also used for proxy-lock rollback in rt_mutex_start_proxy_lock() when invoked from futex_requeue(). In the latter case waiter::task is not current, but remove_waiter() operates on current for the dequeue operation. That results in several problems: 1) the rbtree dequeue happens without waiter::task::pi_lock being held 2) the waiter task's pi_blocked_on state is not cleared, which leaves a dangling pointer primed for UAF around. 3) rt_mutex_adjust_prio_chain() operates on the wrong top priority waiter task Use waiter::task instead of current in all related operations in remove_waiter() to cure those problems. [ tglx: Fixup rt_mutex_adjust_prio_chain(), add a comment and amend the changelog ]

Affected Products

VendorProductVersions
linuxlinux_kernel8161239a8bcce9ad6b537c04a1fa3b5c68bae693, 8161239a8bcce9ad6b537c04a1fa3b5c68bae693, 8161239a8bcce9ad6b537c04a1fa3b5c68bae693, 8161239a8bcce9ad6b537c04a1fa3b5c68bae693, 8161239a8bcce9ad6b537c04a1fa3b5c68bae693, 8161239a8bcce9ad6b537c04a1fa3b5c68bae693, 8161239a8bcce9ad6b537c04a1fa3b5c68bae693, 8161239a8bcce9ad6b537c04a1fa3b5c68bae693, 2.6.39

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
open sourceopen source linux kernelcert_advisory90%

References

  • https://git.kernel.org/stable/c/f3fa3424bceb128d2be4b3745506b22844b87db7
  • https://git.kernel.org/stable/c/838ce5cb5d93c3ab8b27e75bc6ad905a94b752fd
  • https://git.kernel.org/stable/c/d8cce4773c2b23d819baf5abedc62f7b430e8745
  • https://git.kernel.org/stable/c/8a1fc8d698ac5e5916e3082a0f74450d71f9611f
  • https://git.kernel.org/stable/c/6d52dfcb2a5db86e346cf51f8fcf2071b8085166
  • https://git.kernel.org/stable/c/3fb7394a837740770f0d6b4b30567e60786a63f2
  • https://git.kernel.org/stable/c/88614876370aac8ad1050ad785a4c095ba17ac11
  • https://git.kernel.org/stable/c/3bfdc63936dd4773109b7b8c280c0f3b5ae7d349

Related News (16 articles)

Tier B
CERT-FR2d ago
Multiples vulnérabilités dans le noyau Linux d'Ubuntu (21 août 2026)
→ No new info (linked only)
Tier B
CERT-FR9d ago
Multiples vulnérabilités dans le noyau Linux d'Ubuntu (14 août 2026)
→ No new info (linked only)
Tier B
CERT-FR16d ago
Multiples vulnérabilités dans le noyau Linux de Debian LTS (07 août 2026)
→ No new info (linked only)
Tier B
CERT-FR23d ago
Multiples vulnérabilités dans le noyau Linux d'Ubuntu (31 juillet 2026)
→ No new info (linked only)
Tier B
CERT-FR30d ago
Multiples vulnérabilités dans le noyau Linux d'Ubuntu (24 juillet 2026)
→ No new info (linked only)
Tier B
CERT-FR30d ago
Multiples vulnérabilités dans le noyau Linux de Red Hat (24 juillet 2026)
→ No new info (linked only)
Tier C
oss-security45d ago
Re: Linux: GhostLock / CVE-2026-43499 / stack-UAF and LPE in kernels 2.6.39 till 7.1
→ No new info (linked only)
Tier D
SecurityWeek45d ago
15-Year-Old Linux Vulnerability ‘GhostLock’ Earns Researchers $92k From Google
→ No new info (linked only)
Tier C
oss-security45d ago
Re: Linux: GhostLock / CVE-2026-43499 / stack-UAF and LPE in kernels 2.6.39 till 7.1
→ No new info (linked only)
Tier C
oss-security46d ago
Linux: GhostLock / CVE-2026-43499 / stack-UAF and LPE in kernels 2.6.39 till 7.1
→ No new info (linked only)
Tier D
The Hacker News46d ago
15-Year-Old GhostLock Flaw Enables Root and Container Escape on Most Linux Distros
→ No new info (linked only)
Tier E
Hacker News46d ago
We won $92,337 bug bounty using a single kernel 0-day
→ No new info (linked only)
Tier B
BSI Advisories93d ago
[NEU] [mittel] Linux Kernel: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriff
→ No new info (linked only)
Tier A
Microsoft MSRC93d ago
CVE-2026-43499 rtmutex: Use waiter::task instead of current in remove_waiter()
→ No new info (linked only)
Tier C
VulDB94d ago
CVE-2026-43499 | Linux Kernel up to 6.6.139/6.12.85/6.18.26/7.0.3 rtmutex remove_waiter use after free
→ No new info (linked only)
Tier C
Linux Kernel CVEs94d ago
CVE-2026-43499: rtmutex: Use waiter::task instead of current in remove_waiter()
→ No new info (linked only)
CVSS 3.17.8 HIGH
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
8a1fc8d698ac5e5916e3082a0f74450d71f9611f6d52dfcb2a5db86e346cf51f8fcf2071b80851663fb7394a837740770f0d6b4b30567e60786a63f288614876370aac8ad1050ad785a4c095ba17ac113bfdc63936dd4773109b7b8c280c0f3b5ae7d34906.6.1406.12.866.18.277.0.47.1-rc1
PublishedMay 21, 2026
Last enriched45d agov7
Tags
GhostLockCVE-2026-43499LPEDoSCVE-2026-23415CVE-2026-31554CVE-2026-52973KASLR
Trending Score62
Source articles16
Independent9
Info Completeness9/14
Missing: epss, cwe, kev, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-46331EXP
net/sched: fix pedit partial COW leading to page cache corruption
Trending: 65
HIGHCVE-2026-53359EXP
KVM: x86: Fix shadow paging use-after-free due to unexpected role
Trending: 65
HIGHCVE-2026-64600EXP
xfs: resample the data fork mapping after cycling ILOCK
Trending: 56
HIGHCVE-2026-46242EXP
eventpoll: fix ep_remove struct eventpoll / struct file UAF
Trending: 51
HIGHCVE-2026-53366EXP
ipv4: account for fraggap on the paged allocation path
Trending: 50

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
May 21, 2026
Discovered by ZDM
May 21, 2026
Updated: description, affectedVersions, severity
May 21, 2026
Updated: cweIds
Jul 8, 2026
Updated: affectedVersions, cweIds, tags
Jul 8, 2026
Updated: description, activelyExploited, tags
Jul 8, 2026
Updated: exploitAvailable, tags
Jul 9, 2026
Updated: description, tags
Jul 9, 2026
Actively Exploited
Aug 22, 2026
Exploit Available
Aug 22, 2026
Patch Available
Aug 22, 2026

Version History

v7
Last enriched 45d ago
v7Tier C45d ago

Updated description with details on the exploit's dependency on KASLR bypass techniques and added a new tag 'KASLR'.

descriptiontags
via oss-security
v6Tier C45d ago

Updated exploit availability to true and added new CVE IDs related to futex bugs.

exploitAvailabletags
via oss-security
v5Tier C46d ago

Updated description with new details about GhostLock and marked the vulnerability as actively exploited.

descriptionactivelyExploitedtags
via oss-security
v4Tier E46d ago

Updated description with detailed exploit information, added new affected versions, marked as actively exploited, and included new CWE IDs and tags.

affectedVersionscweIdstags
via Hacker News
v3Tier D46d ago

Updated description with details about GhostLock (CVE-2026-43499), changed severity to CRITICAL, and noted that it is actively exploited with an exploit available.

cweIds
via The Hacker News
v2Tier C94d ago

Updated severity to CRITICAL, added affected versions, and provided a new description detailing the vulnerability and its implications.

descriptionaffectedVersionsseverity
via VulDB
v194d ago

Initial creation