PT-2026-93629 · Linux · Linux Kernel
CVE-2026-89988
·
Published
2026-09-16
·
Updated
2026-09-24
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
An issue exists where the
within kprobe blacklist() function traverses the kprobe blacklist without holding the kprobe mutex. When a module is unloaded, the kprobe remove area blacklist() function removes blacklist entries and immediately frees them using kfree(). This can lead to a use-after-free scenario where a concurrent call to within kprobe blacklist() dereferences freed memory. Additionally, within kprobe blacklist() may be executed in atomic or non-preemptible contexts, making it impossible to acquire the sleeping kprobe mutex.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel