tracing: Free histogram the field rejected for a bad modifier

Summary

CVECVE-2026-97921
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2026-09-25 11:17:19 UTC
Updated2026-10-03 11:18:09 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: tracing: Free histogram the field rejected for a bad modifier Writing a hist trigger whose value or variable carries a modifier that is not allowed there leaks the fields that were built for it. __create_val_field() takes the field from parse_expr() and stores it in hist_data->fields[] only after the modifier checks have run: hist_field = parse_expr(hist_data, file, field_str, flags, var_name, &n_subexprs); ... if (hist_field->flags & HIST_FIELD_FL_VAR) { if (hist_field->flags & (...)) goto err; } else { if (hist_field->flags & (...)) goto err; } hist_data->fields[val_idx] = hist_field; Both checks jump past that store, and the err label returns without freeing anything. The error unwinds to create_hist_data(), which calls destroy_hist_data() -> destroy_hist_fields(), and that reaches a field only by walking fields[]. A field that never got there is unreachable. commit e0213434fe3e ("tracing: Do not let histogram values have some modifiers") set ret to -EINVAL and fell through to the store, which left the field owned by fields[] and freed along with the rest of hist_data. Splitting the check into a value case and a variable case replaced that fall-through with a goto that skips it. With CONFIG_DEBUG_KMEMLEAK, 200 writes of # echo 'hist:keys=prev_pid:vals=next_pid.log2' > \ events/sched/sched_switch/trigger each correctly rejected with -EINVAL, leave 332 unreferenced objects (63744 bytes) reported at create_hist_field(); 200 install and remove cycles of a valid trigger leave none. A '.log2' field is two allocations, since create_hist_field() puts the plain field in operands[0] of the log2 field, and both are reported. Use destroy_hist_field() rather than __destroy_hist_field() so that operands[0] is freed as well. It returns early for HIST_FIELD_FL_VAR_REF, which is what an operand owned by hist_data->var_refs[] needs; the rejected field itself is never a var ref, because a var ref never carries a modifier flag.

Risk And Classification

EPSS: 0.002050000 probability, percentile 0.095680000 (date 2026-10-05)

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected 7403630eb94c1d664fb873f967427ef2f6ee3699 a2652fcf96b63e9da04951e4e58e6a0672df695d git Not specified
CNA Linux Linux affected e30fbc618e97b38dbb49f1d44dcd0778d3f23b8c 3d42fed18b2c5707b6332ebe87b789fd768eb01b git Not specified
CNA Linux Linux affected e30fbc618e97b38dbb49f1d44dcd0778d3f23b8c e787361bb6b0026ea3eb4d3fa7a304c7fcb99555 git Not specified
CNA Linux Linux affected e30fbc618e97b38dbb49f1d44dcd0778d3f23b8c b22dc0add7d72b8bd9cae3188db0dd65da1c8652 git Not specified
CNA Linux Linux affected e30fbc618e97b38dbb49f1d44dcd0778d3f23b8c 891c21f6d5673b2a519b536243bfc6dd2d35beb6 git Not specified
CNA Linux Linux affected e30fbc618e97b38dbb49f1d44dcd0778d3f23b8c 230234d12ce42ab04132a32c3a848f07a5d27a71 git Not specified
CNA Linux Linux affected 8d505d06d7330f5d67d3e5e9e1c647fb0b10ddad git Not specified
CNA Linux Linux affected 6.1.33 6.1.189 semver Not specified
CNA Linux Linux affected 6.3.7 6.4 semver Not specified
CNA Linux Linux affected 6.4 Not specified
CNA Linux Linux unaffected 6.4 semver Not specified
CNA Linux Linux unaffected 6.1.189 6.1.* semver Not specified
CNA Linux Linux unaffected 6.6.158 6.6.* semver Not specified
CNA Linux Linux unaffected 6.12.111 6.12.* semver Not specified
CNA Linux Linux unaffected 6.18.53 6.18.* semver Not specified
CNA Linux Linux unaffected 7.2.7 7.2.* semver Not specified
CNA Linux Linux unaffected 7.3-rc3 * original_commit_for_fix Not specified

References

ReferenceSourceLinkTags
git.kernel.org/stable/c/e787361bb6b0026ea3eb4d3fa7a304c7fcb99555 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/230234d12ce42ab04132a32c3a848f07a5d27a71 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/a2652fcf96b63e9da04951e4e58e6a0672df695d 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/891c21f6d5673b2a519b536243bfc6dd2d35beb6 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/b22dc0add7d72b8bd9cae3188db0dd65da1c8652 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/3d42fed18b2c5707b6332ebe87b789fd768eb01b 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report