CVE-2026-97617

Unknown

Last modified

CVE-2026-97617 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: ring-buffer: Check resize_disabled before publishing the new subbuf order ring_buffer_subbuf_order_set() stores the new order and only then walks the CPUs, returning -EBUSY if any of them has resizing disabled. A user mapped buffer has resizing disabled, and __rb_map_vma() reads buffer->subbuf_order without buffer->mutex, so an mmap of an already mapped CPU racing the failing order change sizes the mapping with the new order and inserts pages past the sub-buffer into the VMA. Check the CPUs before storing the new order..

Description

In the Linux kernel, the following vulnerability has been resolved: ring-buffer: Check resize_disabled before publishing the new subbuf order ring_buffer_subbuf_order_set() stores the new order and only then walks the CPUs, returning -EBUSY if any of them has resizing disabled. A user mapped buffer has resizing disabled, and __rb_map_vma() reads buffer->subbuf_order without buffer->mutex, so an mmap of an already mapped CPU racing the failing order change sizes the mapping with the new order and inserts pages past the sub-buffer into the VMA. Check the CPUs before storing the new order.

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
LinuxLinux>= 117c39200d9d760cbd5944bb89efb7b9c51965aa, < f2099644e1b2a2c0805c5240d63ab0522d9d0174; >= 117c39200d9d760cbd5944bb89efb7b9c51965aa, < 9fd4ea952e6ac12a63c3fe89f08ad02771aa2c06; >= 117c39200d9d760cbd5944bb89efb7b9c51965aa, < 32bf47db9237c5b8b6f6aaa5356bb4c79d241f76; >= 117c39200d9d760cbd5944bb89efb7b9c51965aa, < d860c67c051685abb0460b593b193f0f45f4fa92
LinuxLinux6.10

References

Timeline

Published
Last Modified
Status
Received

Frequently Asked Questions

What is CVE-2026-97617?
In the Linux kernel, the following vulnerability has been resolved: ring-buffer: Check resize_disabled before publishing the new subbuf order ring_buffer_subbuf_order_set() stores the new order and only then walks the CPUs, returning -EBUSY if any of them has resizing disabled. A user mapped buffer has resizing disabled, and __rb_map_vma() reads buffer->subbuf_order without buffer->mutex, so an mmap of an already mapped CPU racing the failing order change sizes the mapping with the new order and inserts pages past the sub-buffer into the VMA. Check the CPUs before storing the new order.
How severe is CVE-2026-97617?
Severity scoring for CVE-2026-97617 is pending analysis.
How do I fix CVE-2026-97617?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-97617?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST