PatchSiren cyber security CVE debrief
CVE-2026-45837 Linux CVE debrief
A use-after-free vulnerability in the Linux kernel's bpf subsystem has been addressed. The issue occurred in the arena_vm_close function during a fork operation. This vulnerability could potentially lead to security impacts if exploited. Linux kernel versions 6.9 to 6.12.88, 6.13 to 6.18.30, and 6.19 to 7.0.7 are affected. The vulnerability arises from arena_vm_open() incrementing vml->mmap_count without registering the child VMA in arena->vma_list, leading to use-after-free when the parent is munmapped. The fix involves preventing the arena VMA from being inherited across fork with VM_DONTCOPY and preventing VMA splits via the may_split callback.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- HIGH 7.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-27
- Original CVE updated
- 2026-06-26
- Advisory published
- 2026-05-27
- Advisory updated
- 2026-06-26
Who should care
Linux kernel developers and maintainers, Linux distribution maintainers, and users of Linux kernels within the affected versions. Linux kernel developers should review and apply patches or upgrades. Linux distribution maintainers should update their packages to reflect the fixed versions. Users of affected Linux kernels should prioritize patching or upgrading to mitigate potential security risks.
Why it matters
A use-after-free vulnerability in the Linux kernel's bpf subsystem has been addressed. The issue occurred in the arena_vm_close function during a fork operation. Linux kernel versions 6.9 to 6.12.88, 6.13 to 6.18.30, and 6.19 to 7.0.7 are affected. Defenders should prioritize patching or upgrading to fixed versions to mitigate potential security risks.
- Local attackers could potentially exploit this vulnerability to escalate privileges or cause a denial of service.
- Successful exploitation requires local access and the ability to execute code with elevated privileges.
- Defenders should prioritize patching or upgrading to fixed versions of the Linux kernel to mitigate potential security risks.
- Verification of Linux kernel versions and inventory checks are necessary to determine exposure.
Technical summary
The Linux kernel's bpf subsystem had a use-after-free vulnerability in the arena_vm_close function during fork operations. This was resolved by preventing the arena VMA from being inherited across fork with VM_DONTCOPY and preventing VMA splits via the may_split callback. Affected versions include 6.9 to 6.12.88, 6.13 to 6.18.30, and 6.19 to 7.0.7. The issue arises because arena_vm_open() increments vml->mmap_count but does not register the child VMA in arena->vma_list, leading to a use-after-free when the parent VMA is munmapped.
Defensive priority
Apply patches or upgrade to a fixed version of the Linux kernel.
Recommended defensive actions
- Apply patches or upgrade to a fixed version of the Linux kernel.
- Review and update Linux kernel versions to ensure they are within the fixed ranges.
- Monitor Linux kernel updates for future security patches.
- Verify Linux kernel versions in your environment.
- Check for any exposed assets that need extra review.
- Track exceptions and retest remediated assets.
- Review compensating controls for exposed systems.
Evidence notes
The vulnerability is caused by a use-after-free in the arena_vm_close function on fork. The issue arises because arena_vm_open() increments vml->mmap_count but does not register the child VMA in arena->vma_list. The fix involves preventing the arena VMA from being inherited across fork with VM_DONTCOPY and preventing VMA splits via the may_split callback.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-45837 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-45837
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-45837 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-45837
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/201128fcc7b213d27ab77bc4e89488b41796480f
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/4fddde2a732de60bb97e3307d4eb69ac5f1d2b74
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/723b9fa930cc277c15ce6b9ec9feec828cfac9d7
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/d18099f19e53250f8ad2801498b88cec29d9107a
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.