CVE-2026-80777 Affecting kernel6.18-tools-debuginfo package, versions <1:6.18.48-107.148.amzn2023


Severity

Recommended
high

Based on Amazon Linux security rating.

Threat Intelligence

EPSS
0.21% (10th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-AMZN2023-KERNEL618TOOLSDEBUGINFO-20249645
  • published29 Sept 2026
  • disclosed4 Sept 2026

Introduced: 4 Sep 2026

NewCVE-2026-80777  (opens in a new tab)

How to fix?

Upgrade Amazon-Linux:2023 kernel6.18-tools-debuginfo to version 1:6.18.48-107.148.amzn2023 or higher.
This issue was patched in ALAS2023-2026-3139.

NVD Description

Note: Versions mentioned in the description apply only to the upstream kernel6.18-tools-debuginfo package and not the kernel6.18-tools-debuginfo package as distributed by Amazon-Linux. See How to fix? for Amazon-Linux:2023 relevant fixed versions and status.

In the Linux kernel, the following vulnerability has been resolved:

futex/pi: Plug private futex exec() race

The check for private futexes whether the waiter's mm, which is stored in the futex_key and copied into the pi_state, is the same as the owner's mm is not sufficient for exec(). exec() has a gap where the mm check fails to give the correct answer:

exec() ... exec_release_mm() futex_exec_release() tsk::futex::exit_state = EXITING; cleanup_robust_list();

  1.  tsk::futex::exit_state = OK;
    
    ... old_mm = tsk::mm;
  2. tsk::mm = ->mm;

Between #1 and #2 the check for the mm is wrong as that mm is about to be swapped out and eventually freed.

Plug this gap by:

  1. Setting tsk::futex::exit_state to FUTEX_STATE_DEAD in futex_exec_release()

  2. Setting tsk::futex::exit_state to FUTEX_STATE_OK after the mm has been switched.

From a futex point of view the task is dead after it finished the robust list cleanup up to the point where it sets the state to OK again.