← All Advisories

CVE-2026-97924

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-97924

Key Details

CVECVE-2026-97924
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

tracing/user_events: Don't destroy fields when event removal fails

destroy_user_event() destroys the event's fields before attempting to

remove the trace event call. If user_event_set_call_visible() fails,

e.g. because the event is still enabled and trace_remove_event_call()

returns -EBUSY, the event is left registered with an irreversibly

destroyed field list. Any subsequent interaction with the event then

operates on an empty field list while it is still fully visible in

tracefs.

Move the field destruction after the call removal, and splice the

field list back onto the event when the removal fails so the event

remains in a consistent state. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-97924
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-97924