-

CVE-2026-97933

tracing: Take trace_array reference when opening a tracer options file

In the Linux kernel, the following vulnerability has been resolved:

tracing: Take trace_array reference when opening a tracer options file

When a tracer option file is opened, it is passed a descriptor that points
to an element on the trace_array's topts array. This element has
information to find the trace array and other information. It uses this
element to take a reference of the trace_array so that the trace_array
does not get removed while this file is opened.

Unfortunately, there's a race condition where the element itself could be
freed by the removal of the instance the trace_array represents causing a
use-after-free as this element that is used to find the trace_array to
increment its reference counter is also freed when the instance is
removed.

To solve this, add a trace_array_tracer_options_get() helper function that
will take the address of the element that is passed to the open function
by the inode->i_private pointer and search all the trace_arrays under a
lock to find the one that the element's address is in the range of the
trace_arrays topts array elements. When a match happens, that trace_array's
reference would be increased.

Note, there's a race where if an admin was deleting and creating trace
instances at the same time and the memory of the old trace_array's array
matched the memory of the new trace_array that it could in theory open the
option from the wrong trace array. But we do not care because it would be
stupid to perform that kind of action. As long as the only thing that can
happen is that the option from the wrong trace array is used and doesn't
crash the kernel it will only make the user confused. But if they are
doing something stupid like this, they are already confused, so no harm
done.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 7e2cfbd2d3c86afcd5c26b5c4b1dd251f63c5838
Version < b2890064a12efbeb3b3c093e69e9010dd244c881
Status affected
Version 7e2cfbd2d3c86afcd5c26b5c4b1dd251f63c5838
Version < b2fb87d29ffb3a7a9ccc5acf12898ecb80587427
Status affected
Version 7e2cfbd2d3c86afcd5c26b5c4b1dd251f63c5838
Version < ed0aff60f83a9bdc2f6556376ac79c96b3ce7e80
Status affected
Version 952e477f908048145a5eb2ed3d431d9efc1e1073
Status affected
Version b3183f5f05cd867f5c17122773ca5aa8d07b51af
Status affected
Version bf38c1d29f8bfe9631b62a67f8dd1b8f7efb7139
Status affected
Version 2617afde0c3db285778734b0ccad9a55b4f9cda2
Status affected
Version 586787a0331aa2d7d244e9c4400d2a73295b0cf0
Status affected
Version 5.4.257
Version < 5.5
Status affected
Version 5.10.197
Version < 5.11
Status affected
Version 5.15.133
Version < 5.16
Status affected
Version 6.1.55
Version < 6.2
Status affected
Version 6.5.5
Version < 6.6
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.6
Status affected
Version 0
Version < 6.6
Status unaffected
Version <= 6.12.*
Version 6.12.112
Status unaffected
Version <= 7.2.*
Version 7.2.7
Status unaffected
Version <= *
Version 7.3-rc3
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.19% 0.077
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/b2fb87d29ffb3a7a9ccc5acf12898ecb80587427
https://git.kernel.org/stable/c/ed0aff60f83a9bdc2f6556376ac79c96b3ce7e80
https://git.kernel.org/stable/c/b2890064a12efbeb3b3c093e69e9010dd244c881