CVE-2026-72080

Source
https://cve.org/CVERecord?id=CVE-2026-72080
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72080.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-72080
Downstream
Published
2026-08-15T05:52:29.827Z
Modified
2026-08-18T03:56:37.145468116Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
fs/resctrl: Fix use-after-free during unmount
Details

In the Linux kernel, the following vulnerability has been resolved:

fs/resctrl: Fix use-after-free during unmount

During unmount or failure teardown all mondata structures that contain monitoring event file private data are freed after which kernfs nodes are removed. However, the RDTDELETED flag is never set for the statically allocated default resource group.

A concurrent reader of an event file associated with the default resource group may, after dropping kernfs active protection, block on rdtgroup_mutex while unmount proceeds to free the file private data and destroy the kernfs node without waiting for the reader.

When the mutex is released, the reader wakes up, observes that RDT_DELETED is not set for the default group, and dereferences the already-freed file private data.

The scenario can be depicted as follows: CPU0 CPU1 /* * Default resource group's * monitoring data accessible via * kernfs file with kernfsnode::priv * pointing to a struct mondata. * User opens the file for reading. / rdtgroupmondatashow() / arch encounters fatal error / rdtgroupknlocklive() resctrlexit() atomicinc(&rdtgroupdefault.waitcount) cpusreadlock() kernfsbreakactiveprotection(kn) mutexlock(&rdtgroupmutex) cpusreadlock() resctrlfsteardown() mutexlock(&rdtgroupmutex) rmdirallsub() monputknpriv() / Delete all mondata structures */ rdtgroupdestroyroot() kernfsdestroyroot() rdtgroupdefault.kn = NULL mutexunlock(&rdtgroupmutex) /* * rdtgroupdefault.flags is empty so * rdtgroupknlocklive() returns * &rdtgroup_default */ md = of->kn->priv;

 /* md points to freed mon_data */

Set RDT_DELETED for the default group unconditionally since the flag does not lead to the freeing of this statically allocated group.

Do not allow a new resctrl mount if there are any waiters on default group of previous mount. A new mount will re-initialize the default group that would appear to waiters from previous mount as though the default group is accessible causing them to access the mon_data structures from the previous mount that have been removed.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72080.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
2a65660385444e9d9deffe995c71ee20443ef76e
Fixed
7b7bb07efe41bb646a93c4624aa2bb35df190342
Fixed
7d330a1d663381579b9d5dafa642b1b3158a0ce2
Fixed
52fce648607e0d6a76eeb443d78708c49df1c554

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72080.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.16.0
Fixed
6.18.42
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72080.json"