7.8

CVE-2026-89750

tracing/user_events: Clear copied tracing state before fork duplication

In the Linux kernel, the following vulnerability has been resolved:

tracing/user_events: Clear copied tracing state before fork duplication

dup_task_struct() copies user_event_mm from the parent into the child,
without grabbing a reference to it. user_event_mm_dup() should
replace it, but it leaves that copied pointer unmodified if
user_event_mm_alloc() fails.

When the child exits, user_event_mm_remove() decrements a reference
the child never owned, which ultimately frees user_event_mm, while
the parent still as a stale pointer to it. This creates a UAF, which
KASAN reports as:

    BUG: KASAN: slab-use-after-free in
    current_user_event_mm+0x51/0x1d0 Write of size 4 at addr
    ffff888005010d30 by task init/44

    Call Trace:
     <TASK>
     kasan_report+0xce/0x100
     kasan_check_range+0x10f/0x1e0
     current_user_event_mm+0x51/0x1d0
     user_events_ioctl+0x82e/0x15c0
     __x64_sys_ioctl+0x139/0x1c0
     do_syscall_64+0xce/0x450
     entry_SYSCALL_64_after_hwframe+0x77/0x7f

    Allocated by task 44:
     __kasan_kmalloc+0x8f/0xa0
     __kmalloc_cache_noprof+0x180/0x3a0
     user_event_mm_alloc+0x3c/0x1f0
     current_user_event_mm+0x88/0x1d0

    Freed by task 42:
     __kasan_slab_free+0x43/0x70
     kfree+0x13a/0x390
     process_one_work+0x696/0xf90
     worker_thread+0x420/0xba0

The fix simply clears the copied pointer before any possible failure.
In case of failure, the child then has nothing to free.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 7235759084a4f8524a46bd2638885ff3b34ce279
Version < 33ce55b368b64d65941867add00e7f288cbb8234
Status affected
Version 7235759084a4f8524a46bd2638885ff3b34ce279
Version < 63b39e49a4c9d68e010e96b26fc7374f0864f2b1
Status affected
Version 7235759084a4f8524a46bd2638885ff3b34ce279
Version < 25a0758cf6bdbfddac2be71124c9bd0692f4b0b1
Status affected
Version 7235759084a4f8524a46bd2638885ff3b34ce279
Version < b799f67119aff179719a0b1e12441ebbdaaf62f9
Status affected
Version 7235759084a4f8524a46bd2638885ff3b34ce279
Version < 390f6bd8583d177029d9df4bea6667509e55a765
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.4
Status affected
Version 0
Version < 6.4
Status unaffected
Version <= 6.6.*
Version 6.6.157
Status unaffected
Version <= 6.12.*
Version 6.12.109
Status unaffected
Version <= 6.18.*
Version 6.18.50
Status unaffected
Version <= 7.2.*
Version 7.2.4
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.16% 0.054
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/63b39e49a4c9d68e010e96b26fc7374f0864f2b1
https://git.kernel.org/stable/c/25a0758cf6bdbfddac2be71124c9bd0692f4b0b1
https://git.kernel.org/stable/c/b799f67119aff179719a0b1e12441ebbdaaf62f9
https://git.kernel.org/stable/c/390f6bd8583d177029d9df4bea6667509e55a765
https://git.kernel.org/stable/c/33ce55b368b64d65941867add00e7f288cbb8234