tracing: Take trace_array reference when opening a tracer options file

Summary

CVECVE-2026-97933
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2026-09-25 11:17:20 UTC
Updated2026-09-25 11:17:20 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: tracing: Take trace_array reference when opening a tracer options file When a tracer option file is opened, it is passed a descriptor that points to an element on the trace_array's topts array. This element has information to find the trace array and other information. It uses this element to take a reference of the trace_array so that the trace_array does not get removed while this file is opened. Unfortunately, there's a race condition where the element itself could be freed by the removal of the instance the trace_array represents causing a use-after-free as this element that is used to find the trace_array to increment its reference counter is also freed when the instance is removed. To solve this, add a trace_array_tracer_options_get() helper function that will take the address of the element that is passed to the open function by the inode->i_private pointer and search all the trace_arrays under a lock to find the one that the element's address is in the range of the trace_arrays topts array elements. When a match happens, that trace_array's reference would be increased. Note, there's a race where if an admin was deleting and creating trace instances at the same time and the memory of the old trace_array's array matched the memory of the new trace_array that it could in theory open the option from the wrong trace array. But we do not care because it would be stupid to perform that kind of action. As long as the only thing that can happen is that the option from the wrong trace array is used and doesn't crash the kernel it will only make the user confused. But if they are doing something stupid like this, they are already confused, so no harm done.

Risk And Classification

EPSS: 0.001890000 probability, percentile 0.076680000 (date 2026-09-27)

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected 7e2cfbd2d3c86afcd5c26b5c4b1dd251f63c5838 b2fb87d29ffb3a7a9ccc5acf12898ecb80587427 git Not specified
CNA Linux Linux affected 7e2cfbd2d3c86afcd5c26b5c4b1dd251f63c5838 ed0aff60f83a9bdc2f6556376ac79c96b3ce7e80 git Not specified
CNA Linux Linux affected 952e477f908048145a5eb2ed3d431d9efc1e1073 git Not specified
CNA Linux Linux affected b3183f5f05cd867f5c17122773ca5aa8d07b51af git Not specified
CNA Linux Linux affected bf38c1d29f8bfe9631b62a67f8dd1b8f7efb7139 git Not specified
CNA Linux Linux affected 2617afde0c3db285778734b0ccad9a55b4f9cda2 git Not specified
CNA Linux Linux affected 586787a0331aa2d7d244e9c4400d2a73295b0cf0 git Not specified
CNA Linux Linux affected 5.4.257 5.5 semver Not specified
CNA Linux Linux affected 5.10.197 5.11 semver Not specified
CNA Linux Linux affected 5.15.133 5.16 semver Not specified
CNA Linux Linux affected 6.1.55 6.2 semver Not specified
CNA Linux Linux affected 6.5.5 6.6 semver Not specified
CNA Linux Linux affected 6.6 Not specified
CNA Linux Linux unaffected 6.6 semver Not specified
CNA Linux Linux unaffected 7.2.7 7.2.* semver Not specified
CNA Linux Linux unaffected 7.3-rc3 * original_commit_for_fix Not specified

References

ReferenceSourceLinkTags
git.kernel.org/stable/c/b2fb87d29ffb3a7a9ccc5acf12898ecb80587427 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/ed0aff60f83a9bdc2f6556376ac79c96b3ce7e80 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report