PT-2026-98600 · Linux · Linux

CVE-2026-97936

·

Publicado

2026-09-25

·

Atualizado

2026-09-25

Nenhuma

Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
tracing: Fix memory corruption from the histogram stacktrace modifier
parse field() sets HIST FIELD FL STACKTRACE from the ".stacktrace" modifier before it looks the field name up, and nothing afterwards checks that the name resolved to a field which holds a stacktrace. create hist field() picks HIST FIELD FN STACK on the strength of the field pointer alone, which reads a data loc word from the record and follows its low 16 bits as an offset into the same record. event hist trigger() takes the first word there as an entry count and copies that many longs into a 31 entry array:
n entries = *stack;
memcpy(entries, ++stack, n entries * sizeof(unsigned long));
Neither end of that copy is bounded, and the count is whatever the event holds at the offset, so any field will do:

cd /sys/kernel/tracing/events/sched/sched process fork

echo 'hist:keys=parent pid.stacktrace' > trigger

(true)

BUG: kernel NULL pointer dereference, address: 0000000000000008 RIP: 0010:rb insert color+0x18/0x130 timerqueue linked add+0x7e/0xd0 enqueue hrtimer+0x39/0xb0 hrtimer run queues+0x10f/0x1f0 RIP: 0010:memcpy+0xc/0x30 event hist trigger+0x165/0x690
The timer interrupt landed on the rbtree the copy had already run over. No debug options are needed for this; KASAN reports the same write as an out-of-bounds read of 13835058055416381440 bytes.
Documentation/trace/histogram.rst already states the rule, "must be a long[] type", so enforce it once the name has been resolved. Names which resolve to no field at all, "hitcount.stacktrace" and the common * pseudo-fields, are refused for the same reason: they hold no stacktrace to read.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2026-97936

Produtos afetados

Linux