← All Advisories

Linux Kernel POSIX CPU Timer Firing State Check Uses a Freed Object, Opening a Local Use-After-Free

Last refreshed2026-10-10

Status: UPDATED  |  Advisory ID: CVE-2026-98258

Key Details

CVECVE-2026-98258
CVSS Score / Version7.8 (High) / CVSS v3.1
Updated2026-10-07
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is local; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsLinux Kernel

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux Kernel
SubsystemsOT Supporting Infrastructure
SectorsAll Sectors

What to Know

In the Linux kernel, the following vulnerability has been resolved:

posix-cpu-timers: Prevent freeing a timer which is queued on the expiry list

Kijo analyzed another race in the POSIX CPU timer code:

Commit bf635681c906 converted cpu_timer::firing from a tristate value to a

boolean. This lost the distinction between "not owned by the firing list"

and "still owned, but delivery was canceled". The resulting race is:

expiry handler timer_settime() timer_delete()

-------------- --------------- --------------

collect timer onto

private firing list

firing = true

observes firing = true

firing = false

return TIMER_RETRY

wait for handler

observes firing = false

finish deletion

unhash and free timer

resume list traversal

read freed elist.next

-> UAF

The firing bit is clearly the wrong indicator since that commit.

Check whether the timer is queued on the expiry list or not instead. If it

is queued clear the firing bit to prevent signal delivery as before and

return TIMER_RETRY so the caller unlocks the timer which allows the expiry

code to make progress and remove it from the list. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-98258
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-98258