PT-2026-98601 · Linux · Linux
CVE-2026-97937
·
Publicado
2026-09-25
·
Atualizado
2026-09-25
CVSS v3.1
7.8
Alta
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
In the Linux kernel, the following vulnerability has been resolved:
ftrace: fork: Initialize function graph state before copy exec state()
dup task struct() copies the parent's task struct, including ret stack.
ftrace graph init task() clears the copied function graph state, but it
currently runs after copy exec state().
For non-CLONE VM forks, copy exec state() allocates a new task exec state.
If that allocation fails, copy process() reaches bad fork free and
free task() calls ftrace graph exit task(). Since the child still carries
the parent's ret stack pointer, the unwind frees the parent's active
function graph return stack. The parent subsequently accesses freed memory
from function graph enter regs().
KASAN reports:
[ 22.190920] ==================================================================
[ 22.195899] BUG: KASAN: slab-use-after-free in function graph enter regs+0xa76/0xb90
[ 22.200747] Write of size 8 at addr ff110000054dc0a8 by task repro/1
[ 22.205134]
[ 22.210770] CPU: 0 UID: 0 PID: 1 Comm: repro Not tainted 7.2.0-07732-g9328b3b03bdc-dirty #3 PREEMPT(lazy)
[ 22.212576] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
[ 22.213750] Call Trace:
[ 22.215271]
[ 22.216242] ? ftrace stub direct tramp+0x10/0x10
[ 22.217774] dump stack lvl+0x4e/0x70
[ 22.220531] print report+0x157/0x4b4
[ 22.223202] ? fixup red left+0x9/0x30
[ 22.224407] ? complete report info+0x83/0x110
[ 22.226679] ? function graph enter regs+0xa76/0xb90
[ 22.228084] kasan report+0xce/0x100
[ 22.230109] ? function graph enter regs+0xa76/0xb90
[ 22.232860] ? stack trace save+0x4/0xd0
[ 22.234156] function graph enter regs+0xa76/0xb90
[ 22.236090] ? kasan save stack+0x30/0x50
[ 22.237752] ? pfx function graph enter regs+0x10/0x10
[ 22.238694] ? ring buffer lock reserve+0x345/0xf80
[ 22.239628] ? stack trace save+0x4/0xd0
[ 22.242121] ? stack trace save+0x4/0xd0
[ 22.243588] ftrace graph func+0xda/0x160
[ 22.245362] ? ftrace stub direct tramp+0x10/0x10
[ 22.246520] 0xffffffffa0000095
[ 22.250528] ? stack trace save+0x9/0xd0
[ 22.251757] ? ring buffer unlock commit+0x11d/0x5c0
[ 22.253152] stack trace save+0x9/0xd0
[ 22.254264] kasan save stack+0x30/0x50
[ 22.273631] kasan save track+0x14/0x30
[ 22.276763] kasan save free info+0x3b/0x70
[ 22.278296] kasan slab free+0x43/0x70
[ 22.280157] kmem cache free+0xbf/0x3b0
[ 22.282963] ? ftrace stub direct tramp+0x10/0x10
[ 22.284001] free task+0xa2/0x160
[ 22.285699] ? ftrace stub direct tramp+0x10/0x10
[ 22.286752] copy process+0x2aae/0x7bc0
Initialize the child function graph state immediately after
dup task struct(), before the first fallible operation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Linux