-
CVE-2026-97922
- EPSS 0.2%
- Veröffentlicht 25.09.2026 10:22:41
- Zuletzt bearbeitet 03.10.2026 11:18:09
- Erkennungen
tracing: Free histogram var refs regardless of how often they are referenced
In the Linux kernel, the following vulnerability has been resolved:
tracing: Free histogram var refs regardless of how often they are referenced
Using the same variable three or more times in one hist trigger leaks the
variable reference and its strings when the trigger is removed.
commit 656fe2ba85e8 ("tracing: Use hist trigger's var_ref array to destroy
var_refs") made a trigger's var_refs[] array the only owner of a var ref:
destroy_hist_field() returns early for HIST_FIELD_FL_VAR_REF, so the field
expressions never destroy one. One entry, freed once, no count needed.
commit 8bcebc77e85f ("tracing: Fix histogram code when expression has same
var as value") then made repeated references share one object and added a
count of them. Only the increment side exists, since those expressions
still return early and never drop a reference, so __destroy_hist_field()
sees how many references were created rather than how many are left. It
frees when the decremented count is 0 or 1, so two references work and
three or more leak.
Sharing kept one array entry per object, and create_var_ref() searches and
appends within a single trigger, so nothing outside it holds the object.
Removing a trigger whose variables are still referenced is already refused
by check_var_refs() with -EBUSY. Drop the count and free unconditionally.Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
8bcebc77e85f3d7536f96845a0fe94b1dddb6af0
Version <
a1f1d64a0a9791c842c4646253daf6ac0313eac7
Status
affected
Version
8bcebc77e85f3d7536f96845a0fe94b1dddb6af0
Version <
b513a4c60a7aa1f4b4c2a48544ab003cb36f1e94
Status
affected
Version
8bcebc77e85f3d7536f96845a0fe94b1dddb6af0
Version <
e7b6d67b43caee9183a4374d23641578ea556e6c
Status
affected
Version
8bcebc77e85f3d7536f96845a0fe94b1dddb6af0
Version <
4cff53bb19412c6f2d90b50678de5c3903f7f96a
Status
affected
Version
8bcebc77e85f3d7536f96845a0fe94b1dddb6af0
Version <
94bbd65da4ae26592fa1977a74ee94218ab02a26
Status
affected
Version
8bcebc77e85f3d7536f96845a0fe94b1dddb6af0
Version <
4bddcb346a6cf4615ca77f69a589623b877ca267
Status
affected
Version
ce28d664054df01997baace61d1defca77689798
Status
affected
Version
bf470f051556b610265ea02ad2102de75e8e619c
Status
affected
Version
4.19.100
Version <
4.20
Status
affected
Version
5.4.16
Version <
5.5
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
5.5
Status
affected
Version
0
Version <
5.5
Status
unaffected
Version <=
6.1.*
Version
6.1.189
Status
unaffected
Version <=
6.6.*
Version
6.6.158
Status
unaffected
Version <=
6.12.*
Version
6.12.111
Status
unaffected
Version <=
6.18.*
Version
6.18.53
Status
unaffected
Version <=
7.2.*
Version
7.2.7
Status
unaffected
Version <=
*
Version
7.3-rc3
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.2% | 0.088 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|
https://git.kernel.org/stable/c/e7b6d67b43caee9183a4374d23641578ea556e6c
https://git.kernel.org/stable/c/4cff53bb19412c6f2d90b50678de5c3903f7f96a
https://git.kernel.org/stable/c/94bbd65da4ae26592fa1977a74ee94218ab02a26
https://git.kernel.org/stable/c/4bddcb346a6cf4615ca77f69a589623b877ca267
https://git.kernel.org/stable/c/a1f1d64a0a9791c842c4646253daf6ac0313eac7
https://git.kernel.org/stable/c/b513a4c60a7aa1f4b4c2a48544ab003cb36f1e94