Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

In the Linux kernel, the following vulnerability has been resolved: futex: Prevent robust futex exit race some more A robust futex unlock stores 0… (CVE-2026-74658)

0
Medium
Published: 08/22/2026 (08/22/2026, 18:30:28 UTC)
Source: GCVE Database

Description

A vulnerability in the Linux kernel's futex implementation related to robust futex exit race conditions has been resolved. The issue involves a race condition where waiters on a futex can be left sleeping indefinitely due to lost wake notifications when a woken waiter is killed before it can act. This leads to a scenario where remaining waiters never get woken, causing potential indefinite blocking. The fix augments the robust list exit processing to ensure extra wakeups occur if the futex is owned by another thread but the FUTEX_WAITERS bit is not set. This patch addresses a known shortcoming but does not fully resolve all related futex contention issues, which are being addressed in ongoing kernel development.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/23/2026, 00:10:00 UTC

Technical Analysis

The vulnerability concerns the Linux kernel's futex robust exit handling, where a robust futex unlock operation clears the futex value and wakes a single waiter. If the woken waiter is killed before it can re-arm the FUTEX_WAITERS bit or acquire the futex, and another thread acquires the futex via the fast path, the FUTEX_WAITERS bit is lost. Consequently, remaining waiters can sleep indefinitely behind a free futex. The fix improves robust list exit processing to perform an additional wakeup if the futex is owned by another thread but FUTEX_WAITERS is not set, preventing waiters from sleeping forever. This patch does not address all futex contention and free sequence issues but mitigates this specific race condition.

Potential Impact

Affected systems running vulnerable Linux kernel versions may experience indefinite blocking of threads waiting on futexes due to lost wake notifications. This can lead to application hangs or deadlocks where threads sleep forever waiting on futexes that are no longer properly signaled. There is no indication of remote code execution or privilege escalation from this vulnerability. The impact is primarily denial of service at the thread or process level.

Mitigation Recommendations

A fix for this vulnerability has been implemented in the Linux kernel. Users should update to a kernel version that includes this patch to prevent indefinite futex wait hangs caused by this race condition. Since this is a kernel-level fix, applying the official kernel update from the vendor or distribution is the recommended remediation. Patch status is not explicitly confirmed in the provided data; users should consult their Linux distribution's security advisories for the exact fixed versions and update accordingly.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-m8rg-mx7q-fp2c
Osv Schema Version
1.4.0
Aliases
["CVE-2026-74658"]
Ecosystems
[]
Database Specific Severity
null
Cvss Version
null

Threat ID: 6a8a27f1acd9273b499bc7a2

Added to database: 08/22/2026, 22:51:29 UTC

Last enriched: 08/23/2026, 00:10:00 UTC

Last updated: 08/23/2026, 01:12:15 UTC

Views: 2

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses