← All Advisories

CVE-2026-97937

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-97937

Key Details

CVECVE-2026-97937
CVSS Score / Version7.8 (High) / CVSS v3.1
Updated2026-09-25
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is local; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

ftrace: fork: Initialize function graph state before copy_exec_state()

dup_task_struct() copies the parent's task_struct, including ret_stack.

ftrace_graph_init_task() clears the copied function graph state, but it

currently runs after copy_exec_state().

For non-CLONE_VM forks, copy_exec_state() allocates a new task_exec_state.

If that allocation fails, copy_process() reaches bad_fork_free and

free_task() calls ftrace_graph_exit_task(). Since the child still carries

the parent's ret_stack pointer, the unwind frees the parent's active

function graph return stack. The parent subsequently accesses freed memory

from function_graph_enter_regs().

KASAN reports:

[ 22.190920] ==================================================================

[ 22.195899] BUG: KASAN: slab-use-after-free in function_graph_enter_regs+0xa76/0xb90

[ 22.200747] Write of size 8 at addr ff110000054dc0a8 by task repro/1

[ 22.205134]

[ 22.210770] CPU: 0 UID: 0 PID: 1 Comm: repro Not tainted 7.2.0-07732-g9328b3b03bdc-dirty #3 PREEMPT(lazy)

[ 22.212576] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014

[ 22.213750] Call Trace:

[ 22.215271] <TASK>

[ 22.216242] ? ftrace_stub_direct_tramp+0x10/0x10

[ 22.217774] dump_stack_lvl+0x4e/0x70

[ 22.220531] print_report+0x157/0x4b4

[ 22.223202] ? fixup_red_left+0x9/0x30

[ 22.224407] ? complete_report_info+0x83/0x110

[ 22.226679] ? function_graph_enter_regs+0xa76/0xb90

[ 22.228084] kasan_report+0xce/0x100

[ 22.230109] ? function_graph_enter_regs+0xa76/0xb90

[ 22.232860] ? stack_trace_save+0x4/0xd0

[ 22.234156] function_graph_enter_regs+0xa76/0xb90

[ 22.236090] ? kasan_save_stack+0x30/0x50

[ 22.237752] ? __pfx_function_graph_enter_regs+0x10/0x10

[ 22.238694] ? ring_buffer_lock_reserve+0x345/0xf80

[ 22.239628] ? stack_trace_save+0x4/0xd0

[ 22.242121] ? stack_trace_save+0x4/0xd0

[ 22.243588] ftrace_graph_func+0xda/0x160

[ 22.245362] ? ftrace_stub_direct_tramp+0x10/0x10

[ 22.246520] 0xffffffffa0000095

[ 22.250528] ? stack_trace_save+0x9/0xd0

[ 22.251757] ? ring_buffer_unlock_commit+0x11d/0x5c0

[ 22.253152] stack_trace_save+0x9/0xd0

[ 22.254264] kasan_save_stack+0x30/0x50

[ 22.273631] kasan_save_track+0x14/0x30

[ 22.276763] kasan_save_free_info+0x3b/0x70

[ 22.278296] __kasan_slab_free+0x43/0x70

[ 22.280157] kmem_cache_free+0xbf/0x3b0

[ 22.282963] ? ftrace_stub_direct_tramp+0x10/0x10

[ 22.284001] free_task+0xa2/0x160

[ 22.285699] ? ftrace_stub_direct_tramp+0x10/0x10

[ 22.286752] copy_process+0x2aae/0x7bc0

Initialize the child function graph state immediately after

dup_task_struct(), before the first fallible operation. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-97937
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-97937