7.8
CVE-2026-89750
- EPSS 0.16%
- Veröffentlicht 11.09.2026 19:46:54
- Zuletzt bearbeitet 14.09.2026 13:19:23
- Erkennungen
tracing/user_events: Clear copied tracing state before fork duplication
In the Linux kernel, the following vulnerability has been resolved:
tracing/user_events: Clear copied tracing state before fork duplication
dup_task_struct() copies user_event_mm from the parent into the child,
without grabbing a reference to it. user_event_mm_dup() should
replace it, but it leaves that copied pointer unmodified if
user_event_mm_alloc() fails.
When the child exits, user_event_mm_remove() decrements a reference
the child never owned, which ultimately frees user_event_mm, while
the parent still as a stale pointer to it. This creates a UAF, which
KASAN reports as:
BUG: KASAN: slab-use-after-free in
current_user_event_mm+0x51/0x1d0 Write of size 4 at addr
ffff888005010d30 by task init/44
Call Trace:
<TASK>
kasan_report+0xce/0x100
kasan_check_range+0x10f/0x1e0
current_user_event_mm+0x51/0x1d0
user_events_ioctl+0x82e/0x15c0
__x64_sys_ioctl+0x139/0x1c0
do_syscall_64+0xce/0x450
entry_SYSCALL_64_after_hwframe+0x77/0x7f
Allocated by task 44:
__kasan_kmalloc+0x8f/0xa0
__kmalloc_cache_noprof+0x180/0x3a0
user_event_mm_alloc+0x3c/0x1f0
current_user_event_mm+0x88/0x1d0
Freed by task 42:
__kasan_slab_free+0x43/0x70
kfree+0x13a/0x390
process_one_work+0x696/0xf90
worker_thread+0x420/0xba0
The fix simply clears the copied pointer before any possible failure.
In case of failure, the child then has nothing to free.Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
7235759084a4f8524a46bd2638885ff3b34ce279
Version <
33ce55b368b64d65941867add00e7f288cbb8234
Status
affected
Version
7235759084a4f8524a46bd2638885ff3b34ce279
Version <
63b39e49a4c9d68e010e96b26fc7374f0864f2b1
Status
affected
Version
7235759084a4f8524a46bd2638885ff3b34ce279
Version <
25a0758cf6bdbfddac2be71124c9bd0692f4b0b1
Status
affected
Version
7235759084a4f8524a46bd2638885ff3b34ce279
Version <
b799f67119aff179719a0b1e12441ebbdaaf62f9
Status
affected
Version
7235759084a4f8524a46bd2638885ff3b34ce279
Version <
390f6bd8583d177029d9df4bea6667509e55a765
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
6.4
Status
affected
Version
0
Version <
6.4
Status
unaffected
Version <=
6.6.*
Version
6.6.157
Status
unaffected
Version <=
6.12.*
Version
6.12.109
Status
unaffected
Version <=
6.18.*
Version
6.18.50
Status
unaffected
Version <=
7.2.*
Version
7.2.4
Status
unaffected
Version <=
*
Version
7.3-rc1
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.16% | 0.054 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
https://git.kernel.org/stable/c/63b39e49a4c9d68e010e96b26fc7374f0864f2b1
https://git.kernel.org/stable/c/25a0758cf6bdbfddac2be71124c9bd0692f4b0b1
https://git.kernel.org/stable/c/b799f67119aff179719a0b1e12441ebbdaaf62f9
https://git.kernel.org/stable/c/390f6bd8583d177029d9df4bea6667509e55a765
https://git.kernel.org/stable/c/33ce55b368b64d65941867add00e7f288cbb8234