PT-2026-93655 · Linux · Linux Kernel

CVE-2026-90014

·

Published

2026-09-16

·

Updated

2026-09-24

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A use-after-free crash can occur in the tracing subsystem. The files show event filters and show event triggers do not take a reference to the trace array they are displaying. Consequently, the trace array can be freed via an rmdir operation while a task is reading these files, as they iterate through all events within a trace array instance without a mechanism to prevent the instance from being freed during the read process.
Recommendations Ensure the trace array get() function is called when opening show event filters and show event triggers to maintain a reference to the trace array and prevent it from being freed while the files are open. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-90014
OPENSUSE-SU-2026:11880-1

Affected Products

Linux Kernel