« Volver al listado

CVE-2026-64028

Estado: Pendiente de análisisSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

tracing: Avoid NULL return from hist_field_name() on truncation

hist_field_name() returns "" everywhere except the fully-qualified VAR_REF/EXPR case, where snprintf() truncation returns NULL early and bypasses the bottom NULL->"" guard. Callers don't expect NULL: strcat(expr, hist_field_name(field, 0)) at trace_events_hist.c:1758 and the strcmp() in the sort-key match loop at :4804 both deref it.

system and event_name are bounded by MAX_EVENT_NAME_LEN, but the field name on a VAR_REF is kstrdup'd from a histogram variable name parsed out of the trigger string and has no length cap, so a long enough var name in a fully qualified reference can reach the truncation path.

Leer descripción completaMostrar menos

Keep the length check but leave field_name as "" on overflow.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-64028",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "2e8578364061c4e88ae33bc20c2d6f64f365f6a2",
              "lessThan": "e3f5d42cdc2f167719564693675f1eead81378ea",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "dfd1cd57ee6067301841b7b0967c70f910a51150",
              "lessThan": "37377b39ff86dacbc533275c1155210d4fd5dc91",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "e5c223f46c2e0691461dd97510c15e1f77148872",
              "lessThan": "0402a1d3ddec565132867337ed44514a09d84728",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "9399a92989354e34086f9a5c379493217df83c5e",
              "lessThan": "e91687643c440ca3997d67646e6f80b92edc6703",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "3cb6cb9c5a547a1979ad74f38eefe8e3687d96e0",
              "lessThan": "be4e99038c1603fa6b329d8ee3e364825e17c353",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "0402c60abe769098d77f3b3bd1e29a97922b614b",
              "lessThan": "d6c8b3ebdcdb12b59ad4212acb137cc56cae453d",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "6929e650db8451a9975ac0a631ba2d6e5d1e80ba",
              "lessThan": "915c1254fe0788abddc31095b360e9dc98907a34",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5ec1d1e97de134beed3a5b08235a60fc1c51af96",
              "lessThan": "576ec047d20b368b43c4d5db98c4f2e0f3c101ec",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "kernel/trace/trace_events_hist.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.6.141",
              "lessThan": "6.6.142",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.12.91",
              "lessThan": "6.12.92",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.18.33",
              "lessThan": "6.18.34",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "7.0.10",
              "lessThan": "7.0.11",
              "versionType": "semver"
            }
          ],
          "programFiles": [
            "kernel/trace/trace_events_hist.c"
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-07-19T16:17:42.877",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/0402a1d3ddec565132867337ed44514a09d84728",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/37377b39ff86dacbc533275c1155210d4fd5dc91",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/576ec047d20b368b43c4d5db98c4f2e0f3c101ec",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/915c1254fe0788abddc31095b360e9dc98907a34",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/be4e99038c1603fa6b329d8ee3e364825e17c353",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/d6c8b3ebdcdb12b59ad4212acb137cc56cae453d",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/e3f5d42cdc2f167719564693675f1eead81378ea",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/e91687643c440ca3997d67646e6f80b92edc6703",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Awaiting Analysis",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ntracing: Avoid NULL return from hist_field_name() on truncation\n\nhist_field_name() returns \"\" everywhere except the fully-qualified\nVAR_REF/EXPR case, where snprintf() truncation returns NULL early\nand bypasses the bottom NULL->\"\" guard. Callers don't expect NULL:\nstrcat(expr, hist_field_name(field, 0)) at trace_events_hist.c:1758\nand the strcmp() in the sort-key match loop at :4804 both deref it.\n\nsystem and event_name are bounded by MAX_EVENT_NAME_LEN, but the\nfield name on a VAR_REF is kstrdup'd from a histogram variable\nname parsed out of the trigger string and has no length cap, so\na long enough var name in a fully qualified reference can reach\nthe truncation path.\n\nKeep the length check but leave field_name as \"\" on overflow."
    }
  ],
  "lastModified": "2026-07-30T14:59:47.950",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}