PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-45837 Linux CVE debrief

A use-after-free vulnerability in the Linux kernel's bpf subsystem has been addressed. The issue occurred in the arena_vm_close function during a fork operation. This vulnerability could potentially lead to security impacts if exploited. Linux kernel versions 6.9 to 6.12.88, 6.13 to 6.18.30, and 6.19 to 7.0.7 are affected. The vulnerability arises from arena_vm_open() incrementing vml->mmap_count without registering the child VMA in arena->vma_list, leading to use-after-free when the parent is munmapped. The fix involves preventing the arena VMA from being inherited across fork with VM_DONTCOPY and preventing VMA splits via the may_split callback.

Vendor
Linux
Product
Unknown
CVSS
HIGH 7.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-27
Original CVE updated
2026-06-26
Advisory published
2026-05-27
Advisory updated
2026-06-26

Who should care

Linux kernel developers and maintainers, Linux distribution maintainers, and users of Linux kernels within the affected versions. Linux kernel developers should review and apply patches or upgrades. Linux distribution maintainers should update their packages to reflect the fixed versions. Users of affected Linux kernels should prioritize patching or upgrading to mitigate potential security risks.

Why it matters

A use-after-free vulnerability in the Linux kernel's bpf subsystem has been addressed. The issue occurred in the arena_vm_close function during a fork operation. Linux kernel versions 6.9 to 6.12.88, 6.13 to 6.18.30, and 6.19 to 7.0.7 are affected. Defenders should prioritize patching or upgrading to fixed versions to mitigate potential security risks.

  • Local attackers could potentially exploit this vulnerability to escalate privileges or cause a denial of service.
  • Successful exploitation requires local access and the ability to execute code with elevated privileges.
  • Defenders should prioritize patching or upgrading to fixed versions of the Linux kernel to mitigate potential security risks.
  • Verification of Linux kernel versions and inventory checks are necessary to determine exposure.

Technical summary

The Linux kernel's bpf subsystem had a use-after-free vulnerability in the arena_vm_close function during fork operations. This was resolved by preventing the arena VMA from being inherited across fork with VM_DONTCOPY and preventing VMA splits via the may_split callback. Affected versions include 6.9 to 6.12.88, 6.13 to 6.18.30, and 6.19 to 7.0.7. The issue arises because arena_vm_open() increments vml->mmap_count but does not register the child VMA in arena->vma_list, leading to a use-after-free when the parent VMA is munmapped.

Defensive priority

Apply patches or upgrade to a fixed version of the Linux kernel.

Recommended defensive actions

  • Apply patches or upgrade to a fixed version of the Linux kernel.
  • Review and update Linux kernel versions to ensure they are within the fixed ranges.
  • Monitor Linux kernel updates for future security patches.
  • Verify Linux kernel versions in your environment.
  • Check for any exposed assets that need extra review.
  • Track exceptions and retest remediated assets.
  • Review compensating controls for exposed systems.

Evidence notes

The vulnerability is caused by a use-after-free in the arena_vm_close function on fork. The issue arises because arena_vm_open() increments vml->mmap_count but does not register the child VMA in arena->vma_list. The fix involves preventing the arena VMA from being inherited across fork with VM_DONTCOPY and preventing VMA splits via the may_split callback.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-45837 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-45837

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-45837 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-45837

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/201128fcc7b213d27ab77bc4e89488b41796480f

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/4fddde2a732de60bb97e3307d4eb69ac5f1d2b74

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/723b9fa930cc277c15ce6b9ec9feec828cfac9d7

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/d18099f19e53250f8ad2801498b88cec29d9107a

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.