{"id":"CVE-2026-98258","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nposix-cpu-timers: Prevent freeing a timer which is queued on the expiry list\n\nKijo analyzed another race in the POSIX CPU timer code:\n\nCommit bf635681c906 converted cpu…","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nposix-cpu-timers: Prevent freeing a timer which is queued on the expiry list\n\nKijo analyzed another race in the POSIX CPU timer code:\n\nCommit bf635681c906 converted cpu…","severity":"none","vendor":"Linux","product":"Linux","affected":["Linux >= bf635681c906ad056d1fda325de8d1c12c9f8201 < 9971dac1a77845ff467146915fcbb9170f6a8209","Linux >= bf635681c906ad056d1fda325de8d1c12c9f8201 < 4336e3f47d9d516441066e9a65eaf076790d8d45","Linux >= bf635681c906ad056d1fda325de8d1c12c9f8201 < c21eaa72f02fc6e85621cbe09d303d8fb8bd39cd","Linux 6.13"],"published":"2026-10-06","updated":"2026-10-06","sourceUpdated":"2026-10-06T09:18:14.737","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-98258","references":[{"url":"https://git.kernel.org/stable/c/4336e3f47d9d516441066e9a65eaf076790d8d45","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9971dac1a77845ff467146915fcbb9170f6a8209","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c21eaa72f02fc6e85621cbe09d303d8fb8bd39cd","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-06T08:50:17.429Z","slug":"CVE-2026-98258","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nposix-cpu-timers: Prevent freeing a timer which is queued on the expiry list\n\nKijo analyzed another race in the POSIX CPU timer code:\n\nCommit bf635681c906 converted cpu_timer::firing from a tristate value to a\nboolean. This lost the distinction between \"not owned by the firing list\"\nand \"still owned, but delivery was canceled\". The resulting race is:\n\n    expiry handler              timer_settime()        timer_delete()\n    --------------              ---------------        --------------\n    collect timer onto\n    private firing list\n    firing = true\n                                observes firing = true\n                                firing = false\n                                return TIMER_RETRY\n                                wait for handler\n                                                       observes firing = false\n                                                       finish deletion\n                                                       unhash and free timer\n    resume list traversal\n    read freed elist.next\n    -> UAF\n\nThe firing bit is clearly the wrong indicator since that commit.\n\nCheck whether the timer is queued on the expiry list or not instead. If it\nis queued clear the firing bit to prevent signal delivery as before and\nreturn TIMER_RETRY so the caller unlocks the timer which allows the expiry\ncode to make progress and remove it from the list.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}