HIGHCVE-2026-43178Published Modified CNA Linux
CVE-2026-43178: procfs: fix possible double mmput() in do_procmap_query()
In the Linux kernel, the following vulnerability has been resolved: procfs: fix possible double mmput() in do_procmap_query() When user provides incorrectly sized buffer for build ID for PROCMAP_QUERY we return with -ENAMETOOLONG error. After recent changes this condition happens later, after we unlocked mmap_lock/per-VMA lock and did mmput(), so original goto out is now wrong and will double-mmput() mm_struct. Fix by jumping further to clean up only vm_file and name_buf.
Metrics
- CVSS v3.1
- 7.8
- Severity
- HIGH
- Fixed in
- 0
- Affected Products
- 2
Fix available
06.12.756.18.166.19.661dc9f776705d6db6847c101b98fa4f0e9eb6fa37.08adaff87db143583e08eec4f4e7788f1ef8af94d90f5e87c9b75833b9ef3a4415b92c0247f28ab2ff9fe092084cd04deea18747f58a2304026e76aaa
Affected packages
- Linux / Linux< f9fe092084cd04deea18747f58a2304026e76aaa (from b9b97e6aeb534315f9646b2090d1a5024c6a4e82) · < 8adaff87db143583e08eec4f4e7788f1ef8af94d (from cbc03ce3e6ce7e21214c3f02218213574c1a2d08) · < 90f5e87c9b75833b9ef3a4415b92c0247f28ab2f (from b5cbacd7f86f4f62b8813688c8e73be94e8e1951) · < 61dc9f776705d6db6847c101b98fa4f0e9eb6fa3 (from b5cbacd7f86f4f62b8813688c8e73be94e8e1951) · < 6.12.75 (from 6.12.70) · < 6.18.16 (from 6.18.10)
- Linux / Linux6.19Fixed in 0, 6.12.75, 6.18.16, 6.19.6, 7.0
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H