๐Ÿ” CVE Alert

CVE-2026-97936

UNKNOWN 0.0

tracing: Fix memory corruption from the histogram stacktrace modifier

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: tracing: Fix memory corruption from the histogram stacktrace modifier parse_field() sets HIST_FIELD_FL_STACKTRACE from the ".stacktrace" modifier before it looks the field name up, and nothing afterwards checks that the name resolved to a field which holds a stacktrace. create_hist_field() picks HIST_FIELD_FN_STACK on the strength of the field pointer alone, which reads a __data_loc word from the record and follows its low 16 bits as an offset into the same record. event_hist_trigger() takes the first word there as an entry count and copies that many longs into a 31 entry array: n_entries = *stack; memcpy(entries, ++stack, n_entries * sizeof(unsigned long)); Neither end of that copy is bounded, and the count is whatever the event holds at the offset, so any field will do: # cd /sys/kernel/tracing/events/sched/sched_process_fork # echo 'hist:keys=parent_pid.stacktrace' > trigger # (true) BUG: kernel NULL pointer dereference, address: 0000000000000008 RIP: 0010:rb_insert_color+0x18/0x130 timerqueue_linked_add+0x7e/0xd0 enqueue_hrtimer+0x39/0xb0 __hrtimer_run_queues+0x10f/0x1f0 </IRQ> RIP: 0010:memcpy+0xc/0x30 event_hist_trigger+0x165/0x690 The timer interrupt landed on the rbtree the copy had already run over. No debug options are needed for this; KASAN reports the same write as an out-of-bounds read of 13835058055416381440 bytes. Documentation/trace/histogram.rst already states the rule, "must be a long[] type", so enforce it once the name has been resolved. Names which resolve to no field at all, "hitcount.stacktrace" and the common_* pseudo-fields, are refused for the same reason: they hold no stacktrace to read.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 25, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
cc5fc8bfc961eeb99b7e8dffbeff7a3f6995d314 < e183b84968d4a6ea476d806ea97668405aa56880 cc5fc8bfc961eeb99b7e8dffbeff7a3f6995d314 < 57bfc2a17954d173d2a4182f3b582ffbb23aff64 cc5fc8bfc961eeb99b7e8dffbeff7a3f6995d314 < 55caaf25da2c2bb9b75307e4c868726cb954b1d6 cc5fc8bfc961eeb99b7e8dffbeff7a3f6995d314 < a5e70ba87ca8ebc79b4e63de302d03b0625fe153
Linux / Linux
6.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/e183b84968d4a6ea476d806ea97668405aa56880 git.kernel.org: https://git.kernel.org/stable/c/57bfc2a17954d173d2a4182f3b582ffbb23aff64 git.kernel.org: https://git.kernel.org/stable/c/55caaf25da2c2bb9b75307e4c868726cb954b1d6 git.kernel.org: https://git.kernel.org/stable/c/a5e70ba87ca8ebc79b4e63de302d03b0625fe153