CVE-2026-97933
CVE CVE-2026-97933EUVD EUVD-2026-86787Published 2026-09-25T10:22:48.000Z
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: tracing: Take trace_array reference when opening a tracer options file When a tracer option file is opened, it is passed a descriptor that points to an element on the trace_array's topts array. This element has information to find the trace array and other information. It uses this element to take a reference of the trace_array so that the trace_array does not get removed while this file is opened. Unfortunately, there's a race condition where the element itself could be freed by the removal of the instance the trace_array represents causing a use-after-free as this element that is used to find the trace_array to increment its reference counter is also freed when the instance is removed. To solve this, add a trace_array_tracer_options_get() helper function that will take the address of the element that is passed to the open function by the inode->i_private pointer and search all the trace_arrays under a lock to find the one that the element's address is in the range of the trace_arrays topts array elements. When a match happens, that trace_array's reference would be increased. Note, there's a race where if an admin was deleting and creating trace instances at the same time and the memory of the old trace_array's array matched the memory of the new trace_array that it could in theory open the option from the wrong trace array. But we do not care because it would be stupid to perform that kind of action. As long as the only thing that can happen is that the option from the wrong trace array is used and doesn't crash the kernel it will only make the user confused. But if they are doing something stupid like this, they are already confused, so no harm done.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux 7e2cfbd2d3c86afcd5c26b5c4b1dd251f63c5838 <ed0aff60f83a9bdc2f6556376ac79c96b3ce7e80; 7e2cfbd2d3c86afcd5c26b5c4b1dd251f63c5838 <b2fb87d29ffb3a7a9ccc5acf12898ecb80587427; 6.5.5 <6.6; 952e477f908048145a5eb2ed3d431d9efc1e1073; 586787a0331aa2d7d244e9c4400d2a73295b0cf0; 5.4.257 <5.5; 5.15.133 <5.16; 6.6; patch: 7.2.7; patch: 7.3-rc3; 2617afde0c3db285778734b0ccad9a55b4f9cda2; b3183f5f05cd867f5c17122773ca5aa8d07b51af; patch: 0; 6.1.55 <6.2; 5.10.197 <5.11; bf38c1d29f8bfe9631b62a67f8dd1b8f7efb7139
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.