7.8

CVE-2026-90002

ftrace: Take trace_array reference before accessing its ftrace_ops

In the Linux kernel, the following vulnerability has been resolved:

ftrace: Take trace_array reference before accessing its ftrace_ops

The trace instance files set_ftrace_filter and set_ftrace_notrace was
updated to work with specific trace instances (trace_arrays). The issue is
that when these files are opened, there is a small race window where it
will use the ftrace_ops from the inode->private pointer to get a reference
to the trace_array and then take its reference. The problem is that the
ftrace_ops itself could be freed. If the rmdir on the instance happens at
the same time the set_ftrace_filter file is opened, the rmdir could have
also freed the ftrace_ops and referencing it will cause a use-after-free
bug and crash the kernel.

Instead, pass in the trace_array as the file private data (NULL for the
top level instance), and then pass both the trace_array and the ftrace_ops
to the ftrace_regex_open() function. If the trace_array is NULL, then it
just uses the ftrace_ops without the need to take its reference (like
normal). If the ftrace_ops is NULL, that is only the case for the top
level instance and the global_ops can be used.

This allows the trace_array to have its reference incremented before
touching the ftrace_ops that could also be freed when the instance is.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 591dffdade9f07692a7dd3ed16830ec24e901ece
Version < 177cd8966325f0ffffa3c9381f9e0422019a3973
Status affected
Version 591dffdade9f07692a7dd3ed16830ec24e901ece
Version < 83fd7eca5ab0d3ac3f23bff889175d847e21af06
Status affected
Version 591dffdade9f07692a7dd3ed16830ec24e901ece
Version < cee8f286794df916553d8d445eac5c323ec5b0f8
Status affected
Version 591dffdade9f07692a7dd3ed16830ec24e901ece
Version < 9100191e5acb2e5ea2313f436667bb5fce129f47
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 3.15
Status affected
Version 0
Version < 3.15
Status unaffected
Version <= 6.12.*
Version 6.12.112
Status unaffected
Version <= 6.18.*
Version 6.18.52
Status unaffected
Version <= 7.2.*
Version 7.2.5
Status unaffected
Version <= *
Version 7.3-rc2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.16% 0.053
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/83fd7eca5ab0d3ac3f23bff889175d847e21af06
https://git.kernel.org/stable/c/cee8f286794df916553d8d445eac5c323ec5b0f8
https://git.kernel.org/stable/c/9100191e5acb2e5ea2313f436667bb5fce129f47
https://git.kernel.org/stable/c/177cd8966325f0ffffa3c9381f9e0422019a3973