๐Ÿ” CVE Alert

CVE-2026-97920

UNKNOWN 0.0

tracing: Keep the entry count when the histogram stats allocation fails

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: tracing: Keep the entry count when the histogram stats allocation fails print_entries() uses n_entries both as the number of sort entries and as its own return value, so the -ENOMEM it stores when the stats allocation fails overwrites the count that the cleanup still needs: n_entries = tracing_map_sort_entries(map, ...); if (n_entries < 0) return n_entries; ... if (!stats) { n_entries = -ENOMEM; goto out; } ... out: tracing_map_destroy_sort_entries(sort_entries, n_entries); tracing_map_destroy_sort_entries() takes an unsigned int and loops up to it, so -ENOMEM arrives as 4294967284. It walks an array of at most map->max_elts pointers and calls destroy_sort_entry(), which dereferences and frees, on whatever lies past the end. Reading the hist file of a trigger with a .percent value, with that allocation forced to fail: BUG: KASAN: vmalloc-out-of-bounds in tracing_map_destroy_sort_entries+0xa0/0xb0 Read of size 8 at addr ffffc90000045000 by task init/1 tracing_map_destroy_sort_entries+0xa0/0xb0 hist_show+0x6f7/0x1df0 seq_read_iter+0x2b8/0x1190 vfs_read+0x176/0xa40 The buggy address belongs to a 4-page vmalloc region starting at ffffc90000041000 allocated at tracing_map_sort_entries+0x5c/0xd50 A few pages further the fault is fatal. The registers at the oops confirm the bound: the loop's end pointer less the array start, over the pointer size, is 4294967284. Return the error in a separate variable and leave n_entries holding the count, the way tracing_map_sort_entries() does on its own error path. The stats block is only entered for a value carrying .percent or .graph, which __create_val_field() has rejected since v6.3, so this cannot be reached in mainline as it stands. It becomes reachable again with "tracing: hist: let values keep the percent and graph modifiers", so it should be applied first.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 25, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
abaa5258ce5e5887a9de049f50a85dc023391a1c < 9bd8321f5370295d1ae96dd17d43be3c9edd441b abaa5258ce5e5887a9de049f50a85dc023391a1c < c80b2a8067d58ff7d268ceef781c68b37a16c321 abaa5258ce5e5887a9de049f50a85dc023391a1c < 17e87ce55f877efff1b08fe509e8bf91378cbbc9 abaa5258ce5e5887a9de049f50a85dc023391a1c < 06f5634ec5584954177f9a22e36b3bfb398a971b 93454d1a306ea975294b861d32ffa1e44b20c733 6.1.23 < 6.2
Linux / Linux
6.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/9bd8321f5370295d1ae96dd17d43be3c9edd441b git.kernel.org: https://git.kernel.org/stable/c/c80b2a8067d58ff7d268ceef781c68b37a16c321 git.kernel.org: https://git.kernel.org/stable/c/17e87ce55f877efff1b08fe509e8bf91378cbbc9 git.kernel.org: https://git.kernel.org/stable/c/06f5634ec5584954177f9a22e36b3bfb398a971b