« Volver al listado

CVE-2026-97919

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

tracing: Take the reference before publishing the named histogram trigger

event_hist_trigger_named_init() puts the trigger on the global named_triggers list and only then takes the reference on the trigger it shares its histogram with:

event_hist_trigger_init() fails when alloc_hist_pad() cannot allocate, and nothing takes the trigger back off the list on the way out. event_hist_trigger_parse() frees it, and the next lookup by name reads the freed object:

Do the reference first and publish once it has succeeded, so that nothing which can fail runs after the trigger becomes findable.

Detalles técnicos trazas, registros y código del informe original
	data->ref++;

	save_named_trigger(data->named_data->name, data);

	ret = event_hist_trigger_init(data->named_data);
	if (ret < 0) {
		kfree(data->cmd_ops);
		data->cmd_ops = &trigger_hist_cmd;
	}

	return ret;

 BUG: KASAN: slab-use-after-free in find_named_trigger+0xac/0xc0
 Read of size 8 at addr ffff888009346860 by task init/1
  find_named_trigger+0xac/0xc0
  hist_register_trigger+0xc1/0xa00
  event_hist_trigger_parse+0x3146/0x6af0
  event_trigger_write+0xce/0x160
 Freed by task 67:
  kfree+0x154/0x420
  trigger_kthread_fn+0xfd/0x160

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-97919",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "e53a8dcd36b9ebc9229450eb594ae20e0b2ae0fd",
              "lessThan": "b6fb2f5370a9a6aec325ab2db1ca3d1a881499b8",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "7ab0fc61ce73040f89b12d76a8279995ec283541",
              "lessThan": "2ffaade3611bd9501bc0b9d5d19fc75bfee7a16b",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "7ab0fc61ce73040f89b12d76a8279995ec283541",
              "lessThan": "91c15cdda6033e2439f5975b938754152f3d6e38",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "7ab0fc61ce73040f89b12d76a8279995ec283541",
              "lessThan": "0fe23b8eaba0d3372c66b7b31204408da0715edc",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "ac7ab38c271ba2edaeb0dc35b200ec13339776ae",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "740dab2338f70d93aa8235db5a9541d846d7b21c",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "6.12.34",
              "lessThan": "6.12.112",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.6.94",
              "lessThan": "6.7",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.15.3",
              "lessThan": "6.16",
              "versionType": "semver"
            }
          ],
          "programFiles": [
            "kernel/trace/trace_events_hist.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.16"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.16",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.12.112",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.53",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.7",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc3",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "kernel/trace/trace_events_hist.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-25T11:17:18.923",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/0fe23b8eaba0d3372c66b7b31204408da0715edc",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/2ffaade3611bd9501bc0b9d5d19fc75bfee7a16b",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/91c15cdda6033e2439f5975b938754152f3d6e38",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/b6fb2f5370a9a6aec325ab2db1ca3d1a881499b8",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ntracing: Take the reference before publishing the named histogram trigger\n\nevent_hist_trigger_named_init() puts the trigger on the global\nnamed_triggers list and only then takes the reference on the trigger it\nshares its histogram with:\n\n\tdata->ref++;\n\n\tsave_named_trigger(data->named_data->name, data);\n\n\tret = event_hist_trigger_init(data->named_data);\n\tif (ret < 0) {\n\t\tkfree(data->cmd_ops);\n\t\tdata->cmd_ops = &trigger_hist_cmd;\n\t}\n\n\treturn ret;\n\nevent_hist_trigger_init() fails when alloc_hist_pad() cannot allocate, and\nnothing takes the trigger back off the list on the way out.\nevent_hist_trigger_parse() frees it, and the next lookup by name reads the\nfreed object:\n\n BUG: KASAN: slab-use-after-free in find_named_trigger+0xac/0xc0\n Read of size 8 at addr ffff888009346860 by task init/1\n  find_named_trigger+0xac/0xc0\n  hist_register_trigger+0xc1/0xa00\n  event_hist_trigger_parse+0x3146/0x6af0\n  event_trigger_write+0xce/0x160\n Freed by task 67:\n  kfree+0x154/0x420\n  trigger_kthread_fn+0xfd/0x160\n\nDo the reference first and publish once it has succeeded, so that nothing\nwhich can fail runs after the trigger becomes findable."
    }
  ],
  "lastModified": "2026-10-03T11:18:09.567",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}