-

CVE-2026-97922

tracing: Free histogram var refs regardless of how often they are referenced

In the Linux kernel, the following vulnerability has been resolved:

tracing: Free histogram var refs regardless of how often they are referenced

Using the same variable three or more times in one hist trigger leaks the
variable reference and its strings when the trigger is removed.

commit 656fe2ba85e8 ("tracing: Use hist trigger's var_ref array to destroy
var_refs") made a trigger's var_refs[] array the only owner of a var ref:
destroy_hist_field() returns early for HIST_FIELD_FL_VAR_REF, so the field
expressions never destroy one. One entry, freed once, no count needed.

commit 8bcebc77e85f ("tracing: Fix histogram code when expression has same
var as value") then made repeated references share one object and added a
count of them. Only the increment side exists, since those expressions
still return early and never drop a reference, so __destroy_hist_field()
sees how many references were created rather than how many are left. It
frees when the decremented count is 0 or 1, so two references work and
three or more leak.

Sharing kept one array entry per object, and create_var_ref() searches and
appends within a single trigger, so nothing outside it holds the object.
Removing a trigger whose variables are still referenced is already refused
by check_var_refs() with -EBUSY. Drop the count and free unconditionally.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 8bcebc77e85f3d7536f96845a0fe94b1dddb6af0
Version < a1f1d64a0a9791c842c4646253daf6ac0313eac7
Status affected
Version 8bcebc77e85f3d7536f96845a0fe94b1dddb6af0
Version < b513a4c60a7aa1f4b4c2a48544ab003cb36f1e94
Status affected
Version 8bcebc77e85f3d7536f96845a0fe94b1dddb6af0
Version < e7b6d67b43caee9183a4374d23641578ea556e6c
Status affected
Version 8bcebc77e85f3d7536f96845a0fe94b1dddb6af0
Version < 4cff53bb19412c6f2d90b50678de5c3903f7f96a
Status affected
Version 8bcebc77e85f3d7536f96845a0fe94b1dddb6af0
Version < 94bbd65da4ae26592fa1977a74ee94218ab02a26
Status affected
Version 8bcebc77e85f3d7536f96845a0fe94b1dddb6af0
Version < 4bddcb346a6cf4615ca77f69a589623b877ca267
Status affected
Version ce28d664054df01997baace61d1defca77689798
Status affected
Version bf470f051556b610265ea02ad2102de75e8e619c
Status affected
Version 4.19.100
Version < 4.20
Status affected
Version 5.4.16
Version < 5.5
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 5.5
Status affected
Version 0
Version < 5.5
Status unaffected
Version <= 6.1.*
Version 6.1.189
Status unaffected
Version <= 6.6.*
Version 6.6.158
Status unaffected
Version <= 6.12.*
Version 6.12.111
Status unaffected
Version <= 6.18.*
Version 6.18.53
Status unaffected
Version <= 7.2.*
Version 7.2.7
Status unaffected
Version <= *
Version 7.3-rc3
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.2% 0.088
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/e7b6d67b43caee9183a4374d23641578ea556e6c
https://git.kernel.org/stable/c/4cff53bb19412c6f2d90b50678de5c3903f7f96a
https://git.kernel.org/stable/c/94bbd65da4ae26592fa1977a74ee94218ab02a26
https://git.kernel.org/stable/c/4bddcb346a6cf4615ca77f69a589623b877ca267
https://git.kernel.org/stable/c/a1f1d64a0a9791c842c4646253daf6ac0313eac7
https://git.kernel.org/stable/c/b513a4c60a7aa1f4b4c2a48544ab003cb36f1e94