A race condition in the Linux kernel's ELF core-dump handling allowed concurrent userfaultfd virtual-memory-area (VMA) modifications to merge and free VMAs while elf_core_dump() was iterating them. The flaw, present since userfaultfd was introduced in Linux 4.3, created a kernel use-after-free condition; proof-of-concept code triggered it under KASAN and separately demonstrated kernel heap-data disclosure.
The race could also desynchronize allocation and use of the vma_filesz array, potentially permitting kernel-memory disclosure and constrained out-of-bounds writes. Linux merged a fix into the mainline tree and backported it to stable releases 4.14.114, 4.19.37, and 5.0.10; organizations running affected kernel branches should deploy those or later updates.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
The Project Zero issue for the Linux ELF core-dump/userfaultfd race condition was marked fixed.
The fix was merged into Linus Torvalds' Linux tree as commit 04f5866e41fb70690e28397487d8bd8eea7d712a and backported to stable releases 4.14.114, 4.19.37, and 5.0.10.
A patch addressing the missing locking between ELF core-dump processing and userfaultfd-driven VMA modification was posted publicly to the Linux memory-management mailing list.
After userfaultfd was introduced in Linux v4.3, concurrent userfaultfd VMA operations could merge or free VMAs while elf_core_dump() iterated them, creating a use-after-free and vma_filesz memory-disclosure and constrained out-of-bounds-write risks.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
6 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourcegit.kernel.org
Open sourcebugs.chromium.org
Open sourcecdn.kernel.org
Open sourcecdn.kernel.org
Open sourcecdn.kernel.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.