{"id":"CVE-2026-31555","title":"kernel: futex: Clear stale exiting pointer in futex_lock_pi() retry path (CVE-2026-31555)","summary":"A flaw was found in the Linux kernel. A local user could exploit a race condition within the `futex_lock_pi()` retry path. This vulnerability occurs because a stale pointer to an exiting process is not cleared, leading to a kernel warning.…","severity":"medium","cvss":5.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","cvssSource":"vendor","cwe":"CWE-825","vendor":"Red Hat","product":"Red Hat Enterprise Linux BaseOS (v. 9)","affected":["enterprise_linux 10","enterprise_linux 7","enterprise_linux 8","enterprise_linux 9","enterprise_linux_appstream_v_9","enterprise_linux_baseos_v_9","enterprise_linux_codeready_linux_builder_v_9","enterprise_linux_real_time_for_nfv_v_9","enterprise_linux_real_time_v_9"],"patched":["enterprise_linux_appstream_v_9","enterprise_linux_baseos_v_9","enterprise_linux_codeready_linux_builder_v_9","enterprise_linux_real_time_for_nfv_v_9","enterprise_linux_real_time_v_9"],"published":"2026-04-24","updated":"2026-09-15","sourceUpdated":"2026-09-15T23:44:33+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-31555.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-31555.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-31555"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2461473"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-31555"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-31555"},{"url":"https://lore.kernel.org/linux-cve-announce/2026042456-CVE-2026-31555-ba94@gregkh/T"},{"url":"https://access.redhat.com/errata/RHSA-2026:51035"},{"url":"https://git.kernel.org/stable/c/33095ae3bdde5e5c264d7e88a2f3e7703a26c7aa"},{"url":"https://git.kernel.org/stable/c/e7824ec168d2ac883a213cd1f4d6cc0816002a85"},{"url":"https://git.kernel.org/stable/c/5e8e06bf8909e79b4acd950cf578cfc2f10bbefa"},{"url":"https://git.kernel.org/stable/c/de7c0c04ad868f2cee6671b11c0a6d20421af1da"},{"url":"https://git.kernel.org/stable/c/7475dfad10a05a5bfadebf5f2499bd61b19ed293"},{"url":"https://git.kernel.org/stable/c/92e47ad03e03dbb5515bdf06444bf6b1e147310d"},{"url":"https://git.kernel.org/stable/c/71112e62807d1925dc3ae6188b11f8cfc85aec23"},{"url":"https://git.kernel.org/stable/c/210d36d892de5195e6766c45519dfb1e65f3eb83"}],"tags":["csaf","vex","red-hat","cve.org"],"epss":0.00129,"epssPercentile":0.02882,"ingestedAt":"2026-09-08T15:33:26.990Z","slug":"CVE-2026-31555","body":"## Overview\n\nA flaw was found in the Linux kernel. A local user could exploit a race condition within the `futex_lock_pi()` retry path. This vulnerability occurs because a stale pointer to an exiting process is not cleared, leading to a kernel warning. Successful exploitation of this flaw could result in a system crash, causing a Denial of Service (DoS).\n\n## Vendor advisories\n\n- **RHSA-2026:51035** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9), Red Hat Enterprise Linux BaseOS (v. 9), Red Hat Enterprise Linux CodeReady Linux Builder (v. 9), Red Hat Enterprise Linux Real Time for NFV (v. 9), Red Hat Enterprise Linux Real Time (v. 9) · released 2026-08-06 · [advisory](https://access.redhat.com/errata/RHSA-2026:51035)\n- **Red Hat VEX** · Moderate · affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9 · no fix planned: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9 · updated 2026-09-15 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-31555.json)\n\n**kernel: futex: Clear stale exiting pointer in futex_lock_pi() retry path** — rated Moderate by Red Hat. Released 2026-04-24, updated 2026-09-15.\n\nAffected:\n\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 7\n- Red Hat Enterprise Linux 8\n- Red Hat Enterprise Linux 9\n\nFixed:\n\n- Red Hat Enterprise Linux AppStream (v. 9)\n- Red Hat Enterprise Linux BaseOS (v. 9)\n- Red Hat Enterprise Linux CodeReady Linux Builder (v. 9)\n- Red Hat Enterprise Linux Real Time for NFV (v. 9)\n- Red Hat Enterprise Linux Real Time (v. 9)\n\nNo fix planned:\n\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 7\n- Red Hat Enterprise Linux 8\n- Red Hat Enterprise Linux 9\n\nNot affected:\n\n- Red Hat Enterprise Linux 6\n\n## Remediation\n\nFor details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258\n\nThe system must be rebooted for this update to take effect.\n\nRed Hat recommends treating all kernel errata as security-relevant. Given the kernel's fundamental role, any bug has a higher chance of impacting system security, even if that impact only becomes clear after a fix is published. Therefore, Red Hat prioritizes delivering fixes that improve our customers' overall security posture.\n\nBecause of this proactive approach, a patch may be associa… https://access.redhat.com/errata/RHSA-2026:51035","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":30.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":205508,"id":"CVE-2026-31555","ts":1789576722579,"field":"cvss","old":null,"new":"5.5"},{"seq":205507,"id":"CVE-2026-31555","ts":1789576722579,"field":"severity","old":"none","new":"medium"}]}