-

CVE-2026-97920

tracing: Keep the entry count when the histogram stats allocation fails

In the Linux kernel, the following vulnerability has been resolved:

tracing: Keep the entry count when the histogram stats allocation fails

print_entries() uses n_entries both as the number of sort entries and as
its own return value, so the -ENOMEM it stores when the stats allocation
fails overwrites the count that the cleanup still needs:

	n_entries = tracing_map_sort_entries(map, ...);
	if (n_entries < 0)
		return n_entries;
	...
			if (!stats) {
				n_entries = -ENOMEM;
				goto out;
			}
	...
 out:
	tracing_map_destroy_sort_entries(sort_entries, n_entries);

tracing_map_destroy_sort_entries() takes an unsigned int and loops up to
it, so -ENOMEM arrives as 4294967284. It walks an array of at most
map->max_elts pointers and calls destroy_sort_entry(), which dereferences
and frees, on whatever lies past the end.

Reading the hist file of a trigger with a .percent value, with that
allocation forced to fail:

  BUG: KASAN: vmalloc-out-of-bounds in tracing_map_destroy_sort_entries+0xa0/0xb0
  Read of size 8 at addr ffffc90000045000 by task init/1
   tracing_map_destroy_sort_entries+0xa0/0xb0
   hist_show+0x6f7/0x1df0
   seq_read_iter+0x2b8/0x1190
   vfs_read+0x176/0xa40
  The buggy address belongs to a 4-page vmalloc region starting at
  ffffc90000041000 allocated at tracing_map_sort_entries+0x5c/0xd50

A few pages further the fault is fatal. The registers at the oops confirm
the bound: the loop's end pointer less the array start, over the pointer
size, is 4294967284.

Return the error in a separate variable and leave n_entries holding the
count, the way tracing_map_sort_entries() does on its own error path.

The stats block is only entered for a value carrying .percent or .graph,
which __create_val_field() has rejected since v6.3, so this cannot be
reached in mainline as it stands. It becomes reachable again with
"tracing: hist: let values keep the percent and graph modifiers", so it
should be applied first.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 93454d1a306ea975294b861d32ffa1e44b20c733
Version < 89c978d67ad01ce28223944cc58e95feea177b35
Status affected
Version abaa5258ce5e5887a9de049f50a85dc023391a1c
Version < fe05eeed27128e17d38dbc0af02e4470bcecda89
Status affected
Version abaa5258ce5e5887a9de049f50a85dc023391a1c
Version < 9bd8321f5370295d1ae96dd17d43be3c9edd441b
Status affected
Version abaa5258ce5e5887a9de049f50a85dc023391a1c
Version < c80b2a8067d58ff7d268ceef781c68b37a16c321
Status affected
Version abaa5258ce5e5887a9de049f50a85dc023391a1c
Version < 17e87ce55f877efff1b08fe509e8bf91378cbbc9
Status affected
Version abaa5258ce5e5887a9de049f50a85dc023391a1c
Version < 06f5634ec5584954177f9a22e36b3bfb398a971b
Status affected
Version 6.1.23
Version < 6.1.189
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.2
Status affected
Version 0
Version < 6.2
Status unaffected
Version <= 6.1.*
Version 6.1.189
Status unaffected
Version <= 6.6.*
Version 6.6.158
Status unaffected
Version <= 6.12.*
Version 6.12.111
Status unaffected
Version <= 6.18.*
Version 6.18.53
Status unaffected
Version <= 7.2.*
Version 7.2.7
Status unaffected
Version <= *
Version 7.3-rc3
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.2% 0.088
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/9bd8321f5370295d1ae96dd17d43be3c9edd441b
https://git.kernel.org/stable/c/c80b2a8067d58ff7d268ceef781c68b37a16c321
https://git.kernel.org/stable/c/17e87ce55f877efff1b08fe509e8bf91378cbbc9
https://git.kernel.org/stable/c/06f5634ec5584954177f9a22e36b3bfb398a971b
https://git.kernel.org/stable/c/89c978d67ad01ce28223944cc58e95feea177b35
https://git.kernel.org/stable/c/fe05eeed27128e17d38dbc0af02e4470bcecda89