PT-2026-98599 · Linux · Linux
CVE-2026-97935
·
Publicado
2026-09-25
·
Atualizado
2026-09-25
Nenhuma
Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
tracing: Set the trace clock before registering the histogram trigger
hist register trigger() puts the trigger on the global named triggers
list in cmd ops->init(), and only then sets the trace clock:
if (data->cmd ops->init) {
ret = data->cmd ops->init(data);
if (ret < 0)
goto out;
}
if (hist data->enable timestamps) {
ret = tracing set clock(file->tr, hist data->attrs->clock);
if (ret) {
hist err(tr, HIST ERR SET CLOCK FAIL, errpos(clock));
goto out;
}The clock string is not checked anywhere before that call, so a named
trigger using common timestamp with an unknown clock fails after it has
already become findable. event hist trigger parse() then frees it
without taking it off the list, and the next lookup by name reads the
freed object:
~# cd /sys/kernel/tracing/events/sched/sched switch
~# echo 'hist:name=foo:keys=common pid:ts=common timestamp:clock=bogus' > trigger
bash: echo: write error: Invalid argument
~# echo 'hist:name=foo:keys=common pid' > trigger
BUG: KASAN: slab-use-after-free in find named trigger+0xac/0xc0
Read of size 8 at addr ffff88800915d760 by task init/1
find named trigger+0xac/0xc0
hist register trigger+0xc1/0x900
event hist trigger parse+0x3146/0x6af0
event trigger write+0xce/0x160
Freed by task 63:
kfree+0x154/0x420
trigger kthread fn+0xfd/0x160
Set the clock before the trigger is registered, so that nothing which
can fail runs after it is published, the way commit 6f86bdeab633
("tracing: Fix bad hist from corrupting named triggers list") moved the
registration below the rest of the setup.
tracing set filter buffering() is reference counted, so the init failure
path has to drop the reference that the clock block now takes first.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Linux