PT-2026-98739 · Linux · Linux

CVE-2026-98076

·

Published

2026-09-25

·

Updated

2026-09-30

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A use-after-free issue exists in the tracing/probes component of the Linux kernel. The problem occurs when multiple probes are attached to a single dynamic event (such as kprobe, uprobe, eprobe, or fprobe). The traceprobe define arg fields() function passes name and type strings to trace define field(), which stores pointers to these strings without copying them. Since these strings are owned by the trace probe and freed upon its removal, deleting the first probe that registered the event causes the remaining sibling probes to reference freed memory. This leads to a dangling reference when a field lookup is performed, such as during filter application, which can be triggered via the event filter write function.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-98076

Affected Products

Linux