7.8
CVE-2026-90002
- EPSS 0.16%
- Veröffentlicht 16.09.2026 10:33:12
- Zuletzt bearbeitet 03.10.2026 11:17:45
- Erkennungen
ftrace: Take trace_array reference before accessing its ftrace_ops
In the Linux kernel, the following vulnerability has been resolved: ftrace: Take trace_array reference before accessing its ftrace_ops The trace instance files set_ftrace_filter and set_ftrace_notrace was updated to work with specific trace instances (trace_arrays). The issue is that when these files are opened, there is a small race window where it will use the ftrace_ops from the inode->private pointer to get a reference to the trace_array and then take its reference. The problem is that the ftrace_ops itself could be freed. If the rmdir on the instance happens at the same time the set_ftrace_filter file is opened, the rmdir could have also freed the ftrace_ops and referencing it will cause a use-after-free bug and crash the kernel. Instead, pass in the trace_array as the file private data (NULL for the top level instance), and then pass both the trace_array and the ftrace_ops to the ftrace_regex_open() function. If the trace_array is NULL, then it just uses the ftrace_ops without the need to take its reference (like normal). If the ftrace_ops is NULL, that is only the case for the top level instance and the global_ops can be used. This allows the trace_array to have its reference incremented before touching the ftrace_ops that could also be freed when the instance is.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
591dffdade9f07692a7dd3ed16830ec24e901ece
Version <
177cd8966325f0ffffa3c9381f9e0422019a3973
Status
affected
Version
591dffdade9f07692a7dd3ed16830ec24e901ece
Version <
83fd7eca5ab0d3ac3f23bff889175d847e21af06
Status
affected
Version
591dffdade9f07692a7dd3ed16830ec24e901ece
Version <
cee8f286794df916553d8d445eac5c323ec5b0f8
Status
affected
Version
591dffdade9f07692a7dd3ed16830ec24e901ece
Version <
9100191e5acb2e5ea2313f436667bb5fce129f47
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
3.15
Status
affected
Version
0
Version <
3.15
Status
unaffected
Version <=
6.12.*
Version
6.12.112
Status
unaffected
Version <=
6.18.*
Version
6.18.52
Status
unaffected
Version <=
7.2.*
Version
7.2.5
Status
unaffected
Version <=
*
Version
7.3-rc2
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.16% | 0.053 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
https://git.kernel.org/stable/c/83fd7eca5ab0d3ac3f23bff889175d847e21af06
https://git.kernel.org/stable/c/cee8f286794df916553d8d445eac5c323ec5b0f8
https://git.kernel.org/stable/c/9100191e5acb2e5ea2313f436667bb5fce129f47
https://git.kernel.org/stable/c/177cd8966325f0ffffa3c9381f9e0422019a3973