CVE-2026-97918
In the Linux kernel, the following vulnerability has been resolved:
tracing: Undo the registration when enabling the histogram trigger fails
Commit 6f86bdeab633 ("tracing: Fix bad hist from corrupting named_triggers list") described how a trigger that is registered but not on file->triggers ends up freed while still on the global named_triggers list, and moved the registration down so that hist_trigger_enable() follows it immediately. One path still gets there. hist_trigger_enable() adds the trigger and takes it straight back out when the event cannot be enabled:
so the list walk in hist_unregister_trigger() matches nothing, test stays NULL, and the ->free() that would call del_named_trigger() is skipped. out_unreg falls through to out_free, which frees the trigger anyway:
Leer descripción completaMostrar menos
Leave the trigger where hist_unregister_trigger() can find it and let that undo the registration, which is the only code that knows all of what cmd_ops->init() took: the named list entry, the hist_pad reference, the reference on the trigger a named histogram is shared with, and the copied cmd_ops. It also pairs the failed trace_event_trigger_enable_disable(), whose sm_ref and buffered event reference are otherwise left behind.
Since ->free() releases trigger_data and, for a trigger that does not share its histogram, hist_data with it, out_unreg can no longer fall through to out_free. For a trigger that does share, hist_register_trigger() has already destroyed the caller's hist_data, so the fall-through was reading freed memory there as well.
Move the enable_timestamps check in hist_unregister_trigger() above the ->free() call for the same reason: hist_data does not outlive it once the trigger being removed is the one that owns it.
Detalles técnicos trazas, registros y código del informe original
list_add_tail_rcu(&data->list, &file->triggers);
update_cond_flag(file);
if (trace_event_trigger_enable_disable(file, 1) < 0) {
list_del_rcu(&data->list);
update_cond_flag(file);
ret--;
}
BUG: KASAN: slab-use-after-free in find_named_trigger+0xac/0xc0
Read of size 8 at addr ffff8880091d3160 by task init/1
find_named_trigger+0xac/0xc0
hist_register_trigger+0xc1/0xa00
event_hist_trigger_parse+0x3146/0x6af0
event_trigger_write+0xce/0x160
Freed by task 69:
kfree+0x154/0x420
trigger_kthread_fn+0xfd/0x160CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.20%
- Percentil entre todas las CVEs puntuadas: 9
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-97918",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "067fe038e70f6e64960d26a79c4df5f1413d0f13",
"lessThan": "c7ee2d5733574d4694f7c0035e4381f54c1fca27",
"versionType": "git"
},
{
"status": "affected",
"version": "067fe038e70f6e64960d26a79c4df5f1413d0f13",
"lessThan": "51b07104d563d4be2be34158d3b9d922ca417642",
"versionType": "git"
},
{
"status": "affected",
"version": "067fe038e70f6e64960d26a79c4df5f1413d0f13",
"lessThan": "bfa6bc11aef93a3d9db0ac9564b734849a9d959b",
"versionType": "git"
},
{
"status": "affected",
"version": "067fe038e70f6e64960d26a79c4df5f1413d0f13",
"lessThan": "92383cef66791a0c63a2f27755cadbdb2fbf270b",
"versionType": "git"
}
],
"programFiles": [
"kernel/trace/trace_events_hist.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "4.17"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "4.17",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.12.112",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.53",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.2.7",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc3",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"kernel/trace/trace_events_hist.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-25T11:17:18.807",
"references": [
{
"url": "https://git.kernel.org/stable/c/51b07104d563d4be2be34158d3b9d922ca417642",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/92383cef66791a0c63a2f27755cadbdb2fbf270b",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/bfa6bc11aef93a3d9db0ac9564b734849a9d959b",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/c7ee2d5733574d4694f7c0035e4381f54c1fca27",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ntracing: Undo the registration when enabling the histogram trigger fails\n\nCommit 6f86bdeab633 (\"tracing: Fix bad hist from corrupting named_triggers\nlist\") described how a trigger that is registered but not on file->triggers\nends up freed while still on the global named_triggers list, and moved the\nregistration down so that hist_trigger_enable() follows it immediately. One\npath still gets there. hist_trigger_enable() adds the trigger and takes it\nstraight back out when the event cannot be enabled:\n\n\tlist_add_tail_rcu(&data->list, &file->triggers);\n\n\tupdate_cond_flag(file);\n\n\tif (trace_event_trigger_enable_disable(file, 1) < 0) {\n\t\tlist_del_rcu(&data->list);\n\t\tupdate_cond_flag(file);\n\t\tret--;\n\t}\n\nso the list walk in hist_unregister_trigger() matches nothing, test stays\nNULL, and the ->free() that would call del_named_trigger() is skipped.\nout_unreg falls through to out_free, which frees the trigger anyway:\n\n BUG: KASAN: slab-use-after-free in find_named_trigger+0xac/0xc0\n Read of size 8 at addr ffff8880091d3160 by task init/1\n find_named_trigger+0xac/0xc0\n hist_register_trigger+0xc1/0xa00\n event_hist_trigger_parse+0x3146/0x6af0\n event_trigger_write+0xce/0x160\n Freed by task 69:\n kfree+0x154/0x420\n trigger_kthread_fn+0xfd/0x160\n\nLeave the trigger where hist_unregister_trigger() can find it and let that\nundo the registration, which is the only code that knows all of what\ncmd_ops->init() took: the named list entry, the hist_pad reference, the\nreference on the trigger a named histogram is shared with, and the copied\ncmd_ops. It also pairs the failed trace_event_trigger_enable_disable(),\nwhose sm_ref and buffered event reference are otherwise left behind.\n\nSince ->free() releases trigger_data and, for a trigger that does not share\nits histogram, hist_data with it, out_unreg can no longer fall through to\nout_free. For a trigger that does share, hist_register_trigger() has\nalready destroyed the caller's hist_data, so the fall-through was reading\nfreed memory there as well.\n\nMove the enable_timestamps check in hist_unregister_trigger() above the\n->free() call for the same reason: hist_data does not outlive it once the\ntrigger being removed is the one that owns it."
}
],
"lastModified": "2026-10-03T11:18:09.447",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}