PT-2026-98597 · Linux · Linux
CVE-2026-97933
·
Publicado
2026-09-25
·
Atualizado
2026-09-25
Nenhuma
Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
tracing: Take trace array reference when opening a tracer options file
When a tracer option file is opened, it is passed a descriptor that points
to an element on the trace array's topts array. This element has
information to find the trace array and other information. It uses this
element to take a reference of the trace array so that the trace array
does not get removed while this file is opened.
Unfortunately, there's a race condition where the element itself could be
freed by the removal of the instance the trace array represents causing a
use-after-free as this element that is used to find the trace array to
increment its reference counter is also freed when the instance is
removed.
To solve this, add a trace array tracer options get() helper function that
will take the address of the element that is passed to the open function
by the inode->i private pointer and search all the trace arrays under a
lock to find the one that the element's address is in the range of the
trace arrays topts array elements. When a match happens, that trace array's
reference would be increased.
Note, there's a race where if an admin was deleting and creating trace
instances at the same time and the memory of the old trace array's array
matched the memory of the new trace array that it could in theory open the
option from the wrong trace array. But we do not care because it would be
stupid to perform that kind of action. As long as the only thing that can
happen is that the option from the wrong trace array is used and doesn't
crash the kernel it will only make the user confused. But if they are
doing something stupid like this, they are already confused, so no harm
done.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Linux