CVE-2026-97935
In the Linux kernel, the following vulnerability has been resolved:
tracing: Set the trace clock before registering the histogram trigger
hist_register_trigger() puts the trigger on the global named_triggers list in cmd_ops->init(), and only then sets the trace clock:
The clock string is not checked anywhere before that call, so a named trigger using common_timestamp with an unknown clock fails after it has already become findable. event_hist_trigger_parse() then frees it without taking it off the list, and the next lookup by name reads the freed object:
~# cd /sys/kernel/tracing/events/sched/sched_switch ~# echo 'hist:name=foo:keys=common_pid:ts=common_timestamp:clock=bogus' > trigger bash: echo: write error: Invalid argument ~# echo 'hist:name=foo:keys=common_pid' > trigger
Leer descripción completaMostrar menos
Set the clock before the trigger is registered, so that nothing which can fail runs after it is published, the way commit 6f86bdeab633 ("tracing: Fix bad hist from corrupting named_triggers list") moved the registration below the rest of the setup.
tracing_set_filter_buffering() is reference counted, so the init failure path has to drop the reference that the clock block now takes first.
Detalles técnicos trazas, registros y código del informe original
if (data->cmd_ops->init) {
ret = data->cmd_ops->init(data);
if (ret < 0)
goto out;
}
if (hist_data->enable_timestamps) {
ret = tracing_set_clock(file->tr, hist_data->attrs->clock);
if (ret) {
hist_err(tr, HIST_ERR_SET_CLOCK_FAIL, errpos(clock));
goto out;
}
BUG: KASAN: slab-use-after-free in find_named_trigger+0xac/0xc0
Read of size 8 at addr ffff88800915d760 by task init/1
find_named_trigger+0xac/0xc0
hist_register_trigger+0xc1/0x900
event_hist_trigger_parse+0x3146/0x6af0
event_trigger_write+0xce/0x160
Freed by task 63:
kfree+0x154/0x420
trigger_kthread_fn+0xfd/0x160CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.17%
- Percentil entre todas las CVEs puntuadas: 5
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-97935",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "a4072fe85ba3671720cab0788291af953db27318",
"lessThan": "cc6c4cf565b0c187c61ffd2e67a4dfb2427675ad",
"versionType": "git"
},
{
"status": "affected",
"version": "a4072fe85ba3671720cab0788291af953db27318",
"lessThan": "cfad128171f8e2237a3c723d6478ef2cfb3b9127",
"versionType": "git"
},
{
"status": "affected",
"version": "a4072fe85ba3671720cab0788291af953db27318",
"lessThan": "65d1e28198f344832a8a63e8ccf84b8f65b92a32",
"versionType": "git"
},
{
"status": "affected",
"version": "a4072fe85ba3671720cab0788291af953db27318",
"lessThan": "6ede78d0563a2a3ae3e46f9c07cedb5d79645429",
"versionType": "git"
}
],
"programFiles": [
"kernel/trace/trace_events_hist.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "4.17"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "4.17",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.12.112",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.53",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.2.7",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc3",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"kernel/trace/trace_events_hist.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-25T11:17:20.850",
"references": [
{
"url": "https://git.kernel.org/stable/c/65d1e28198f344832a8a63e8ccf84b8f65b92a32",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/6ede78d0563a2a3ae3e46f9c07cedb5d79645429",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/cc6c4cf565b0c187c61ffd2e67a4dfb2427675ad",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/cfad128171f8e2237a3c723d6478ef2cfb3b9127",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ntracing: Set the trace clock before registering the histogram trigger\n\nhist_register_trigger() puts the trigger on the global named_triggers\nlist in cmd_ops->init(), and only then sets the trace clock:\n\n\tif (data->cmd_ops->init) {\n\t\tret = data->cmd_ops->init(data);\n\t\tif (ret < 0)\n\t\t\tgoto out;\n\t}\n\n\tif (hist_data->enable_timestamps) {\n\t\tret = tracing_set_clock(file->tr, hist_data->attrs->clock);\n\t\tif (ret) {\n\t\t\thist_err(tr, HIST_ERR_SET_CLOCK_FAIL, errpos(clock));\n\t\t\tgoto out;\n\t\t}\n\nThe clock string is not checked anywhere before that call, so a named\ntrigger using common_timestamp with an unknown clock fails after it has\nalready become findable. event_hist_trigger_parse() then frees it\nwithout taking it off the list, and the next lookup by name reads the\nfreed object:\n\n ~# cd /sys/kernel/tracing/events/sched/sched_switch\n ~# echo 'hist:name=foo:keys=common_pid:ts=common_timestamp:clock=bogus' > trigger\n bash: echo: write error: Invalid argument\n ~# echo 'hist:name=foo:keys=common_pid' > trigger\n\n BUG: KASAN: slab-use-after-free in find_named_trigger+0xac/0xc0\n Read of size 8 at addr ffff88800915d760 by task init/1\n find_named_trigger+0xac/0xc0\n hist_register_trigger+0xc1/0x900\n event_hist_trigger_parse+0x3146/0x6af0\n event_trigger_write+0xce/0x160\n Freed by task 63:\n kfree+0x154/0x420\n trigger_kthread_fn+0xfd/0x160\n\nSet the clock before the trigger is registered, so that nothing which\ncan fail runs after it is published, the way commit 6f86bdeab633\n(\"tracing: Fix bad hist from corrupting named_triggers list\") moved the\nregistration below the rest of the setup.\n\ntracing_set_filter_buffering() is reference counted, so the init failure\npath has to drop the reference that the clock block now takes first."
}
],
"lastModified": "2026-10-03T11:18:19.153",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}