← All Advisories

CVE-2026-97919

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-97919

Key Details

CVECVE-2026-97919
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

tracing: Take the reference before publishing the named histogram trigger

event_hist_trigger_named_init() puts the trigger on the global

named_triggers list and only then takes the reference on the trigger it

shares its histogram with:

data->ref++;

save_named_trigger(data->named_data->name, data);

ret = event_hist_trigger_init(data->named_data);

if (ret < 0) {

kfree(data->cmd_ops);

data->cmd_ops = &trigger_hist_cmd;

}

return ret;

event_hist_trigger_init() fails when alloc_hist_pad() cannot allocate, and

nothing takes the trigger back off the list on the way out.

event_hist_trigger_parse() frees it, and the next lookup by name reads the

freed object:

BUG: KASAN: slab-use-after-free in find_named_trigger+0xac/0xc0

Read of size 8 at addr ffff888009346860 by task init/1

find_named_trigger+0xac/0xc0

hist_register_trigger+0xc1/0xa00

event_hist_trigger_parse+0x3146/0x6af0

event_trigger_write+0xce/0x160

Freed by task 67:

kfree+0x154/0x420

trigger_kthread_fn+0xfd/0x160

Do the reference first and publish once it has succeeded, so that nothing

which can fail runs after the trigger becomes findable. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-97919
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-97919