CVE-2026-89750
N/A
Summary
In the Linux kernel, the following vulnerability has been resolved:
tracing/user_events: Clear copied tracing state before fork duplication
dup_task_struct() copies user_event_mm from the parent into the child, without grabbing a reference to it. user_event_mm_dup() should replace it, but it leaves that copied pointer unmodified if user_event_mm_alloc() fails.
When the child exits, user_event_mm_remove() decrements a reference the child never owned, which ultimately frees user_event_mm, while the parent still as a stale pointer to it. This creates a UAF, which KASAN reports as:
BUG: KASAN: slab-use-after-free in
current_user_event_mm+0x51/0x1d0 Write of size 4 at addr
ffff888005010d30 by task init/44
Call Trace:
<TASK>
kasan_report+0xce/0x100
kasan_check_range+0x10f/0x1e0
current_user_event_mm+0x51/0x1d0
user_events_ioctl+0x82e/0x15c0
__x64_sys_ioctl+0x139/0x1c0
do_syscall_64+0xce/0x450
entry_SYSCALL_64_after_hwframe+0x77/0x7f
Allocated by task 44:
__kasan_kmalloc+0x8f/0xa0
__kmalloc_cache_noprof+0x180/0x3a0
user_event_mm_alloc+0x3c/0x1f0
current_user_event_mm+0x88/0x1d0
Freed by task 42:
__kasan_slab_free+0x43/0x70
kfree+0x13a/0x390
process_one_work+0x696/0xf90
worker_thread+0x420/0xba0
The fix simply clears the copied pointer before any possible failure. In case of failure, the child then has nothing to free.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 7235759084a4f8524a46bd2638885ff3b34ce279 < 63b39e49a4c9d68e010e96b26fc7374f0864f2b1 | affected |
| Linux | Linux | 7235759084a4f8524a46bd2638885ff3b34ce279 < 25a0758cf6bdbfddac2be71124c9bd0692f4b0b1 | affected |
| Linux | Linux | 7235759084a4f8524a46bd2638885ff3b34ce279 < b799f67119aff179719a0b1e12441ebbdaaf62f9 | affected |
| Linux | Linux | 7235759084a4f8524a46bd2638885ff3b34ce279 < 390f6bd8583d177029d9df4bea6667509e55a765 | affected |
| Linux | Linux | 6.4 | affected |
| Linux | Linux | 0 < 6.4 | unaffected |
| Linux | Linux | 6.12.109 <= 6.12.* | unaffected |
| Linux | Linux | 6.18.50 <= 6.18.* | unaffected |
| Linux | Linux | 7.2.4 <= 7.2.* | unaffected |
| Linux | Linux | 7.3-rc1 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/63b39e49a4c9d68e010e96b26fc7374f0864f2b1
- https://git.kernel.org/stable/c/25a0758cf6bdbfddac2be71124c9bd0692f4b0b1
- https://git.kernel.org/stable/c/b799f67119aff179719a0b1e12441ebbdaaf62f9
- https://git.kernel.org/stable/c/390f6bd8583d177029d9df4bea6667509e55a765
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.