CVE-2026-98260: exec: Cleanup POSIX timers right after de_thread()
exec: Cleanup POSIX timers right after dethread()
exec: Cleanup POSIX timers right after dethread()
A non-leader thread must execute exec() while a per-thread CPU POSIX timer associated with that thread is armed. An exec-stage operation must then fail after de_thread() but before begin_new_exec() reaches the timer cleanup.
The task can exit with a timer node still queued in its POSIX CPU timer tree. exit_itimers() frees the timer, and later reaping the task can erase the freed node from the rbtree, creating a use-after-free condition.
Prioritize systems where applications create armed per-thread CPU timers and allow non-leader threads to call exec(). The described failure additionally depends on errors in unshare_files(), set_mm_exe_file(), exec_mmap(), or exec_task_namespaces() after de_thread().