« Volver al listado

CVE-2026-74477

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

uprobes: Fix NULL pointer dereference in hprobe_expire()

Forking a task that has a pending uretprobe can oops the kernel with a NULL pointer dereference in the clone() path:

This was found on real hosts on Meta fleet.

I've got the impression that this is what is happening:

Only take the extra reference when the uprobe is non-NULL; a NULL means it is gone and is the correct value to return.

Detalles técnicos trazas, registros y código del informe original
  BUG: kernel NULL pointer dereference, address: 0000000000000018
  Oops: 0002 [#1] SMP NOPTI
  RIP: 0010:hprobe_expire
  CR2: 0000000000000018
  Call Trace:
   uprobe_copy_process
   copy_process
   kernel_clone
   __x64_sys_clone
   do_syscall_64
   entry_SYSCALL_64_after_hwframe

  CPU 1                          CPU 2 (traced task)
  -----                          -------------------
                                 hit uprobe, prepare_uretprobe():
                                   hprobe LEASED, refcount >= 1
  uprobe_unregister()
    put_uprobe(): refcount -> 0
                                 fork() -> dup_utask()
                                   hprobe_expire(hprobe, true)
                                     try_get_uprobe() -> NULL
                                     get_uprobe(NULL)   <-- Oops

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-74477",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "dd1a7567784e2b1f80258be04f57bcfa82c997eb",
              "lessThan": "3bd35a5e272a1b7a3fb43acad9bdc599281b13fa",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "dd1a7567784e2b1f80258be04f57bcfa82c997eb",
              "lessThan": "06c275a6c0a953ef1d763d11a6891fcc69ae2ac0",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "dd1a7567784e2b1f80258be04f57bcfa82c997eb",
              "lessThan": "cc679d7a6303e84d769f2afcde1fc51c51f127cd",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "kernel/events/uprobes.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.13"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.13",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.18.44",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.1.8",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "kernel/events/uprobes.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-08-15T13:17:52.497",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/06c275a6c0a953ef1d763d11a6891fcc69ae2ac0",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/3bd35a5e272a1b7a3fb43acad9bdc599281b13fa",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/cc679d7a6303e84d769f2afcde1fc51c51f127cd",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nuprobes: Fix NULL pointer dereference in hprobe_expire()\n\nForking a task that has a pending uretprobe can oops the kernel with a\nNULL pointer dereference in the clone() path:\n\n  BUG: kernel NULL pointer dereference, address: 0000000000000018\n  Oops: 0002 [#1] SMP NOPTI\n  RIP: 0010:hprobe_expire\n  CR2: 0000000000000018\n  Call Trace:\n   uprobe_copy_process\n   copy_process\n   kernel_clone\n   __x64_sys_clone\n   do_syscall_64\n   entry_SYSCALL_64_after_hwframe\n\nThis was found on real hosts on Meta fleet.\n\nI've got the impression that this is what is happening:\n\n  CPU 1                          CPU 2 (traced task)\n  -----                          -------------------\n                                 hit uprobe, prepare_uretprobe():\n                                   hprobe LEASED, refcount >= 1\n  uprobe_unregister()\n    put_uprobe(): refcount -> 0\n                                 fork() -> dup_utask()\n                                   hprobe_expire(hprobe, true)\n                                     try_get_uprobe() -> NULL\n                                     get_uprobe(NULL)   <-- Oops\n\nOnly take the extra reference when the uprobe is non-NULL; a NULL means\nit is gone and is the correct value to return."
    }
  ],
  "lastModified": "2026-08-17T06:19:43.777",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}