← All Advisories

CVE-2026-90013

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-90013

Key Details

CVECVE-2026-90013
CVSS Score / Version7.8 (High) / CVSS v3.1
Updated2026-10-03
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is local; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

tracing: Take trace_array reference when opening options file

The options files do not take the trace_array reference for the options

they represent. This could cause a use-after-free kernel crash if one of

these files is opened by one task and another task removes the instance

that the option is for. Because it doesn't take a reference upon opening,

it will not stop the removal which will free the options descriptor that

is being used.

As the options are somewhat dynamic in their creation at boot up, each

file represents a flag in the trace_array. The trace_array has an array of

indexes to represent each of these flags that is stored in the

trace_flags_index array. The address of the index array element is used to

pass to the inode->i_private pointer. Then that element is read which

holds the index (which represents the flag) and then the index is used to

calculate the trace_array descriptor from its trace_flags_index array.

One issue is that the index element can not be referenced until the

trace_array's reference is taken. To handle this, create a new helper

function called: trace_array_options_get() that will iterate all the

existing trace_arrays in the ftrace_trace_arrays list (under the

trace_types_lock), and compare the passed in address of the index element

with the entire array of the trace_array's trace_flags_index array.

If it matches, then up the corresponding trace_array's reference and

return. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-90013
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-90013