PT-2026-98599 · Linux · Linux
CVE-2026-97935
·
Published
2026-09-25
·
Updated
2026-09-25
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
tracing: Set the trace clock before registering the histogram trigger
hist register trigger() puts the trigger on the global named triggers
list in cmd ops->init(), and only then sets the trace clock:
if (data->cmd ops->init) {
ret = data->cmd ops->init(data);
if (ret < 0)
goto out;
}
if (hist data->enable timestamps) {
ret = tracing set clock(file->tr, hist data->attrs->clock);
if (ret) {
hist err(tr, HIST ERR SET CLOCK FAIL, errpos(clock));
goto out;
}The clock string is not checked anywhere before that call, so a named
trigger using common timestamp with an unknown clock fails after it has
already become findable. event hist trigger parse() then frees it
without taking it off the list, and the next lookup by name reads the
freed object:
~# cd /sys/kernel/tracing/events/sched/sched switch
~# echo 'hist:name=foo:keys=common pid:ts=common timestamp:clock=bogus' > trigger
bash: echo: write error: Invalid argument
~# echo 'hist:name=foo:keys=common pid' > trigger
BUG: KASAN: slab-use-after-free in find named trigger+0xac/0xc0
Read of size 8 at addr ffff88800915d760 by task init/1
find named trigger+0xac/0xc0
hist register trigger+0xc1/0x900
event hist trigger parse+0x3146/0x6af0
event trigger write+0xce/0x160
Freed by task 63:
kfree+0x154/0x420
trigger kthread fn+0xfd/0x160
Set the clock before the trigger is registered, so that nothing which
can fail runs after it is published, the way commit 6f86bdeab633
("tracing: Fix bad hist from corrupting named triggers list") moved the
registration below the rest of the setup.
tracing set filter buffering() is reference counted, so the init failure
path has to drop the reference that the clock block now takes first.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux