PT-2026-98583 · Linux · Linux
CVE-2026-97919
·
Publicado
2026-09-25
·
Atualizado
2026-09-25
Nenhuma
Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
tracing: Take the reference before publishing the named histogram trigger
event hist trigger named init() puts the trigger on the global
named triggers list and only then takes the reference on the trigger it
shares its histogram with:
data->ref++;
save named trigger(data->named data->name, data);
ret = event hist trigger init(data->named data);
if (ret < 0) {
kfree(data->cmd ops);
data->cmd ops = &trigger hist cmd;
}
return ret;event hist trigger init() fails when alloc hist pad() cannot allocate, and
nothing takes the trigger back off the list on the way out.
event hist trigger parse() frees it, and the next lookup by name reads the
freed object:
BUG: KASAN: slab-use-after-free in find named trigger+0xac/0xc0
Read of size 8 at addr ffff888009346860 by task init/1
find named trigger+0xac/0xc0
hist register trigger+0xc1/0xa00
event hist trigger parse+0x3146/0x6af0
event trigger write+0xce/0x160
Freed by task 67:
kfree+0x154/0x420
trigger kthread fn+0xfd/0x160
Do the reference first and publish once it has succeeded, so that nothing
which can fail runs after the trigger becomes findable.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Linux