← All Advisories

CVE-2026-97935

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-97935

Key Details

CVECVE-2026-97935
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

tracing: Set the trace clock before registering the histogram trigger

hist_register_trigger() puts the trigger on the global named_triggers

list in cmd_ops->init(), and only then sets the trace clock:

if (data->cmd_ops->init) {

ret = data->cmd_ops->init(data);

if (ret < 0)

goto out;

}

if (hist_data->enable_timestamps) {

ret = tracing_set_clock(file->tr, hist_data->attrs->clock);

if (ret) {

hist_err(tr, HIST_ERR_SET_CLOCK_FAIL, errpos(clock));

goto out;

}

The clock string is not checked anywhere before that call, so a named

trigger using common_timestamp with an unknown clock fails after it has

already become findable. event_hist_trigger_parse() then frees it

without taking it off the list, and the next lookup by name reads the

freed object:

~# cd /sys/kernel/tracing/events/sched/sched_switch

~# echo 'hist:name=foo:keys=common_pid:ts=common_timestamp:clock=bogus' > trigger

bash: echo: write error: Invalid argument

~# echo 'hist:name=foo:keys=common_pid' > trigger

BUG: KASAN: slab-use-after-free in find_named_trigger+0xac/0xc0

Read of size 8 at addr ffff88800915d760 by task init/1

find_named_trigger+0xac/0xc0

hist_register_trigger+0xc1/0x900

event_hist_trigger_parse+0x3146/0x6af0

event_trigger_write+0xce/0x160

Freed by task 63:

kfree+0x154/0x420

trigger_kthread_fn+0xfd/0x160

Set the clock before the trigger is registered, so that nothing which

can fail runs after it is published, the way commit 6f86bdeab633

("tracing: Fix bad hist from corrupting named_triggers list") moved the

registration below the rest of the setup.

tracing_set_filter_buffering() is reference counted, so the init failure

path has to drop the reference that the clock block now takes first. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-97935
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-97935