CVE-2026-93137

Source
https://cve.org/CVERecord?id=CVE-2026-93137
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93137.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-93137
Downstream
Published
2026-09-17T16:11:38Z
Modified
2026-09-18T03:48:44Z
Summary
bpf: Fix use-after-free on mm_struct in bpf_find_vma()
Details

In the Linux kernel, the following vulnerability has been resolved:

bpf: Fix use-after-free on mm_struct in bpf_find_vma()

bpf_find_vma() reads task->mm and calls mmap_read_trylock(mm) without holding a reference on the mm. On a foreign task, a concurrent exit_mm() can free the mm_struct between the lockless read and the trylock, resulting in a use-after-free. mm_struct is not SLAB_TYPESAFE_BY_RCU.

For the current task, task->mm is stable. For a foreign task, pin the mm under task->alloc_lock and release it with mmput_async(), mirroring commit d8e27d2d22b6 ("bpf: fix mm lifecycle in open-coded task_vma iterator"). Use spin_trylock() instead of get_task_mm() so BPF context does not block on alloc_lock. Reject irqs-disabled contexts and !CONFIG_MMU on the foreign-task path because dropping the mm reference is not safe there.

Race:

CPU0 (BPF program) CPU1 (exiting task) ============================ ========================== bpf_find_vma(foreign_task): mm = task->mm exit_mm(): task->mm = NULL mmput(mm) -> frees mm_struct mmap_read_trylock(mm) // UAF on mm

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/93xxx/CVE-2026-93137.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
7c7e3d31e7856a8260a254f8c71db416f7f9f5a1
Fixed
db347840d6b6ee9bb9b8e4a985d4b4419f9f3200
Fixed
8e1101fc4118019a69c96ced4aec93164f89cbd5
Fixed
c7ad910e987008e125eeff448892e86852173384
Fixed
86d54cf069fc5ae2e111c87933bebf6eb527978e
Fixed
2b2a903bee56d312539046d9defa8023eec94760
Fixed
47b079e2117a2ee52e21f8b72935900c702fc0b5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93137.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.17.0
Fixed
6.1.188
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.157
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.110
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.52
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93137.json"