PT-2026-98583 · Linux · Linux

CVE-2026-97919

·

Publicado

2026-09-25

·

Atualizado

2026-09-25

Nenhuma

Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
tracing: Take the reference before publishing the named histogram trigger
event hist trigger named init() puts the trigger on the global named triggers list and only then takes the reference on the trigger it shares its histogram with:
data->ref++;

save named trigger(data->named data->name, data);

ret = event hist trigger init(data->named data);
if (ret < 0) {
	kfree(data->cmd ops);
	data->cmd ops = &trigger hist cmd;
}

return ret;
event hist trigger init() fails when alloc hist pad() cannot allocate, and nothing takes the trigger back off the list on the way out. event hist trigger parse() frees it, and the next lookup by name reads the freed object:
BUG: KASAN: slab-use-after-free in find named trigger+0xac/0xc0 Read of size 8 at addr ffff888009346860 by task init/1 find named trigger+0xac/0xc0 hist register trigger+0xc1/0xa00 event hist trigger parse+0x3146/0x6af0 event trigger write+0xce/0x160 Freed by task 67: kfree+0x154/0x420 trigger kthread fn+0xfd/0x160
Do the reference first and publish once it has succeeded, so that nothing which can fail runs after the trigger becomes findable.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2026-97919

Produtos afetados

Linux