PT-2026-98599 · Linux · Linux

CVE-2026-97935

·

Publicado

2026-09-25

·

Atualizado

2026-09-25

Nenhuma

Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
tracing: Set the trace clock before registering the histogram trigger
hist register trigger() puts the trigger on the global named triggers list in cmd ops->init(), and only then sets the trace clock:
if (data->cmd ops->init) {
	ret = data->cmd ops->init(data);
	if (ret < 0)
		goto out;
}

if (hist data->enable timestamps) {
	ret = tracing set clock(file->tr, hist data->attrs->clock);
	if (ret) {
		hist err(tr, HIST ERR SET CLOCK FAIL, errpos(clock));
		goto out;
	}
The clock string is not checked anywhere before that call, so a named trigger using common timestamp with an unknown clock fails after it has already become findable. event hist trigger parse() then frees it without taking it off the list, and the next lookup by name reads the freed object:
~# cd /sys/kernel/tracing/events/sched/sched switch ~# echo 'hist:name=foo:keys=common pid:ts=common timestamp:clock=bogus' > trigger bash: echo: write error: Invalid argument ~# echo 'hist:name=foo:keys=common pid' > trigger
BUG: KASAN: slab-use-after-free in find named trigger+0xac/0xc0 Read of size 8 at addr ffff88800915d760 by task init/1 find named trigger+0xac/0xc0 hist register trigger+0xc1/0x900 event hist trigger parse+0x3146/0x6af0 event trigger write+0xce/0x160 Freed by task 63: kfree+0x154/0x420 trigger kthread fn+0xfd/0x160
Set the clock before the trigger is registered, so that nothing which can fail runs after it is published, the way commit 6f86bdeab633 ("tracing: Fix bad hist from corrupting named triggers list") moved the registration below the rest of the setup.
tracing set filter buffering() is reference counted, so the init failure path has to drop the reference that the clock block now takes first.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2026-97935

Produtos afetados

Linux