CVE-2026-97919
In the Linux kernel, the following vulnerability has been resolved:
tracing: Take the reference before publishing the named histogram trigger
event_hist_trigger_named_init() puts the trigger on the global named_triggers list and only then takes the reference on the trigger it shares its histogram with:
event_hist_trigger_init() fails when alloc_hist_pad() cannot allocate, and nothing takes the trigger back off the list on the way out. event_hist_trigger_parse() frees it, and the next lookup by name reads the freed object:
Do the reference first and publish once it has succeeded, so that nothing which can fail runs after the trigger becomes findable.
Detalles técnicos trazas, registros y código del informe original
data->ref++;
save_named_trigger(data->named_data->name, data);
ret = event_hist_trigger_init(data->named_data);
if (ret < 0) {
kfree(data->cmd_ops);
data->cmd_ops = &trigger_hist_cmd;
}
return ret;
BUG: KASAN: slab-use-after-free in find_named_trigger+0xac/0xc0
Read of size 8 at addr ffff888009346860 by task init/1
find_named_trigger+0xac/0xc0
hist_register_trigger+0xc1/0xa00
event_hist_trigger_parse+0x3146/0x6af0
event_trigger_write+0xce/0x160
Freed by task 67:
kfree+0x154/0x420
trigger_kthread_fn+0xfd/0x160CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.20%
- Percentil entre todas las CVEs puntuadas: 9
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-97919",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "e53a8dcd36b9ebc9229450eb594ae20e0b2ae0fd",
"lessThan": "b6fb2f5370a9a6aec325ab2db1ca3d1a881499b8",
"versionType": "git"
},
{
"status": "affected",
"version": "7ab0fc61ce73040f89b12d76a8279995ec283541",
"lessThan": "2ffaade3611bd9501bc0b9d5d19fc75bfee7a16b",
"versionType": "git"
},
{
"status": "affected",
"version": "7ab0fc61ce73040f89b12d76a8279995ec283541",
"lessThan": "91c15cdda6033e2439f5975b938754152f3d6e38",
"versionType": "git"
},
{
"status": "affected",
"version": "7ab0fc61ce73040f89b12d76a8279995ec283541",
"lessThan": "0fe23b8eaba0d3372c66b7b31204408da0715edc",
"versionType": "git"
},
{
"status": "affected",
"version": "ac7ab38c271ba2edaeb0dc35b200ec13339776ae",
"versionType": "git"
},
{
"status": "affected",
"version": "740dab2338f70d93aa8235db5a9541d846d7b21c",
"versionType": "git"
},
{
"status": "affected",
"version": "6.12.34",
"lessThan": "6.12.112",
"versionType": "semver"
},
{
"status": "affected",
"version": "6.6.94",
"lessThan": "6.7",
"versionType": "semver"
},
{
"status": "affected",
"version": "6.15.3",
"lessThan": "6.16",
"versionType": "semver"
}
],
"programFiles": [
"kernel/trace/trace_events_hist.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6.16"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "6.16",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.12.112",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.53",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.2.7",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc3",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"kernel/trace/trace_events_hist.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-25T11:17:18.923",
"references": [
{
"url": "https://git.kernel.org/stable/c/0fe23b8eaba0d3372c66b7b31204408da0715edc",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/2ffaade3611bd9501bc0b9d5d19fc75bfee7a16b",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/91c15cdda6033e2439f5975b938754152f3d6e38",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/b6fb2f5370a9a6aec325ab2db1ca3d1a881499b8",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ntracing: Take the reference before publishing the named histogram trigger\n\nevent_hist_trigger_named_init() puts the trigger on the global\nnamed_triggers list and only then takes the reference on the trigger it\nshares its histogram with:\n\n\tdata->ref++;\n\n\tsave_named_trigger(data->named_data->name, data);\n\n\tret = event_hist_trigger_init(data->named_data);\n\tif (ret < 0) {\n\t\tkfree(data->cmd_ops);\n\t\tdata->cmd_ops = &trigger_hist_cmd;\n\t}\n\n\treturn ret;\n\nevent_hist_trigger_init() fails when alloc_hist_pad() cannot allocate, and\nnothing takes the trigger back off the list on the way out.\nevent_hist_trigger_parse() frees it, and the next lookup by name reads the\nfreed object:\n\n BUG: KASAN: slab-use-after-free in find_named_trigger+0xac/0xc0\n Read of size 8 at addr ffff888009346860 by task init/1\n find_named_trigger+0xac/0xc0\n hist_register_trigger+0xc1/0xa00\n event_hist_trigger_parse+0x3146/0x6af0\n event_trigger_write+0xce/0x160\n Freed by task 67:\n kfree+0x154/0x420\n trigger_kthread_fn+0xfd/0x160\n\nDo the reference first and publish once it has succeeded, so that nothing\nwhich can fail runs after the trigger becomes findable."
}
],
"lastModified": "2026-10-03T11:18:09.567",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}