← back
CVE-2026-43499high

rtmutex: Use waiter::task instead of current in remove_waiter()

49Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendcvss 7.8epss 0.7%
from disclosure to weapon37 days
Published on NVDMay 21
1st PoC+37d
exploitation probability
0.7%top 49% of all CVEs
observed exploitation
nono source reports it
86 public exploit(s)
In the Linux kernel, the following vulnerability has been resolved: rtmutex: Use waiter::task instead of current in remove_waiter() remove_waiter() is used by the slowlock paths, but it is also used for proxy-lock rollback in rt_mutex_start_proxy_lock() when invoked from futex_requeue(). In the latter case waiter::task is not current, but remove_waiter() operates on current for the dequeue operation. That results in several problems: 1) the rbtree dequeue happens without waiter::task::pi_lock being held 2) the waiter task's pi_blocked_on state is not cleared, which leaves a dangling pointer primed for UAF around. 3) rt_mutex_adjust_prio_chain() operates on the wrong top priority waiter task Use waiter::task instead of current in all related operations in remove_waiter() to cure those problems. [ tglx: Fixup rt_mutex_adjust_prio_chain(), add a comment and amend the changelog ]
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
Linux · Linux
public PoCs found86
githubgithub.com/BuSung-dev/Root-My-Galaxy758githubgithub.com/JoinChang/ghostlock-oneplus238githubgithub.com/x-spy/CVE-2026-43499-popsicle221githubgithub.com/MobiusM/CVE-2026-43499144githubgithub.com/alex193a/Root-My-Pixel120githubgithub.com/Linuxoid-cn/Mi8E5-Unlocker-by-CVE-2026-4349992githubgithub.com/pubglite55/oppo-ghostlock61githubgithub.com/Linuxoid-cn/CVE-2026-43499-Poc-Analysis46githubgithub.com/Colorful-glassblock/duchamp-root45githubgithub.com/CakesTwix/Android-CVE-2026-4349943githubgithub.com/BuSung-dev/CVE-2026-43499-S25U39githubgithub.com/p2p3p/GhostLock-for-OnePlus36githubgithub.com/woshimaniubi8/CVE-2026-43499-root-KernelSU18githubgithub.com/gagaltotal/CVE-2026-43499-PoC-Scanner17githubgithub.com/boxiaolanya2008/CVE-2026-43499-Neo11Plus16githubgithub.com/PeronGH/ghostlock-selinux-disabler15githubgithub.com/wxxsfxyzm/GhostLock-Galaxy13githubgithub.com/cuteaplane/GhostLock-for-OnePlus15T12githubgithub.com/xianwan1314/CVE-2026-43499-Poc-Analysis10githubgithub.com/tc3650/CVE-2026-43499-armv79githubgithub.com/WitAqua-tools/Root-My-Device9githubgithub.com/ctn-Qvo/auto_extract_offsets8githubgithub.com/datfooldive/ghostlock-emerald8githubgithub.com/1ndevelopment/CVE-2026-43499-S267githubgithub.com/Wtrwx/smt878u-ionstack-poc7githubgithub.com/Yakayna/SpringPeace7githubgithub.com/SlightNeko/ghostlock-rothko6githubgithub.com/Bartixxx32/CVE-2026-43499-OnePlus156githubgithub.com/0xBlackash/CVE-2026-434996githubgithub.com/Meowkis/tcp-zerocopy-sm6githubgithub.com/sorrow404Null/CVE-2026-43499-RMX52006githubgithub.com/soralis0912/CVE-2026-43499-aristotle-apk5githubgithub.com/Bailan766/rmx3888-cve-2026-43499-config5githubgithub.com/joehquak/Mi8E5-Unlocker-by-CVE-2026-434995githubgithub.com/Thiasap/oppo-pgem10-ghostlock5githubgithub.com/NothingFumo/ghostlock-aresin4githubgithub.com/Petalrain224/CVE-2026-43499-Redmi-Turbo54githubgithub.com/oopnv70-lab/ghostlock-honor-aak4githubgithub.com/Witaqua-tools/Root-My-Device4githubgithub.com/soralis0912/CVE-2026-43499-aristotle3githubgithub.com/ctnBobong32/auto_extract_offsets3githubgithub.com/dmcdtc/openvz-cve-patch-20263githubgithub.com/LuZe0y/pd2425-cve-2026-43499-config3githubgithub.com/taoubi1/ghostlock-sm-a155f3githubgithub.com/fusiondrive/CVE-2026-43499-S24U3githubgithub.com/veygax/HORiZonstack2githubgithub.com/No-22-Github/UnPlus2githubgithub.com/eroorvbsyes-hotmail/CVE-2026-43499_x86_Exploit2githubgithub.com/jason5545/ghostlock-myron-tw2githubgithub.com/oopnv70-lab/ghostlock-apk1githubgithub.com/soralis0912/CVE-2026-43499-warhol-root1githubgithub.com/ctn-Qvo/CVE-2026-43499-so-build1githubgithub.com/onesmiledx/CVE-2026-434991githubgithub.com/HYCQAQ/Logitech-G-Cloud-GhostLock-CVE-2026-434991githubgithub.com/dnlid/CVE-2026-434991githubgithub.com/inforcqb/CVE-2026-43499-pja1101githubgithub.com/233laoliu/mt6985-CVE-2026-434991githubgithub.com/2932796375github/CVE-2026-43499_OPPO-MT68351githubgithub.com/mumaosong/cve-2026-43499-CyberMeowfia1githubgithub.com/MiaPatsune/cve-2026-434991githubgithub.com/suominen/ghostlock1githubgithub.com/DistrictBlauw/Ace3-GhostLock-Preload0githubgithub.com/fancyzll/CVE-2026-43499_OPPO-MT68350githubgithub.com/d224407/CVE-2026-434990githubgithub.com/HORKimhab/CVE-2026-434990githubgithub.com/Kananosa/CVE-2026-43499-For-Xiaomi-17T-chagall0githubgithub.com/mumaosong/CVE-2026-43499-cloudflare-gate0githubgithub.com/ayyy7128/CVE-2026-43499-jinghu0githubgithub.com/fuukliam/vivo-x-fold6-ghostlock0githubgithub.com/fusiondrive/CVE-2026-43499-A360githubgithub.com/soralis0912/CVE-2026-43499-pmg110-root0githubgithub.com/CatXiaoShi/cve-2026-434990githubgithub.com/ruik-tech/Root-My-Galaxy0githubgithub.com/OhLookItsTheIRS/Root-My-Galaxy-tests0githubgithub.com/zzzxxxxxxxxxx/GhostLock-GOT-W290githubgithub.com/geecjdj/CVE-2026-434990githubgithub.com/qianmo-xw/CVE-2026-43499-popsicle0githubgithub.com/ctnBobong32/CVE-2026-43499-so-build0githubgithub.com/qsvggff-spec/oppo-A5-PRO-5G-CVE-2026-434990githubgithub.com/xiaohj233/ghostlock-x200-root0githubgithub.com/oopnv70-lab/ghostlock-skeleton0githubgithub.com/Cxyofficial/x200-cve-2026-434990githubgithub.com/justsoman/CyberMeowfia-ace30githubgithub.com/oopnv70-lab/ghostlock-skeleton-v20githubgithub.com/DistrictBlauw/CyberMeowfia-ace30githubgithub.com/caspy123/CVE-2026-434990
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.