All of lore.kernel.org
 help / color / mirror / Atom feed
* CVE-2026-89750: tracing/user_events: Clear copied tracing state before fork duplication
@ 2026-09-11 19:47 Greg Kroah-Hartman
  0 siblings, 0 replies; only message in thread
From: Greg Kroah-Hartman @ 2026-09-11 19:47 UTC (permalink / raw)
  To: linux-cve-announce; +Cc: Greg Kroah-Hartman

From: Greg Kroah-Hartman <gregkh@kernel.org>

Description
===========

In the Linux kernel, the following vulnerability has been resolved:

tracing/user_events: Clear copied tracing state before fork duplication

dup_task_struct() copies user_event_mm from the parent into the child,
without grabbing a reference to it. user_event_mm_dup() should
replace it, but it leaves that copied pointer unmodified if
user_event_mm_alloc() fails.

When the child exits, user_event_mm_remove() decrements a reference
the child never owned, which ultimately frees user_event_mm, while
the parent still as a stale pointer to it. This creates a UAF, which
KASAN reports as:

    BUG: KASAN: slab-use-after-free in
    current_user_event_mm+0x51/0x1d0 Write of size 4 at addr
    ffff888005010d30 by task init/44

    Call Trace:
     <TASK>
     kasan_report+0xce/0x100
     kasan_check_range+0x10f/0x1e0
     current_user_event_mm+0x51/0x1d0
     user_events_ioctl+0x82e/0x15c0
     __x64_sys_ioctl+0x139/0x1c0
     do_syscall_64+0xce/0x450
     entry_SYSCALL_64_after_hwframe+0x77/0x7f

    Allocated by task 44:
     __kasan_kmalloc+0x8f/0xa0
     __kmalloc_cache_noprof+0x180/0x3a0
     user_event_mm_alloc+0x3c/0x1f0
     current_user_event_mm+0x88/0x1d0

    Freed by task 42:
     __kasan_slab_free+0x43/0x70
     kfree+0x13a/0x390
     process_one_work+0x696/0xf90
     worker_thread+0x420/0xba0

The fix simply clears the copied pointer before any possible failure.
In case of failure, the child then has nothing to free.

The Linux kernel CVE team has assigned CVE-2026-89750 to this issue.


Affected and fixed versions
===========================

	Issue introduced in 6.4 with commit 7235759084a4f8524a46bd2638885ff3b34ce279 and fixed in 6.12.109 with commit 63b39e49a4c9d68e010e96b26fc7374f0864f2b1
	Issue introduced in 6.4 with commit 7235759084a4f8524a46bd2638885ff3b34ce279 and fixed in 6.18.50 with commit 25a0758cf6bdbfddac2be71124c9bd0692f4b0b1
	Issue introduced in 6.4 with commit 7235759084a4f8524a46bd2638885ff3b34ce279 and fixed in 7.2.4 with commit b799f67119aff179719a0b1e12441ebbdaaf62f9
	Issue introduced in 6.4 with commit 7235759084a4f8524a46bd2638885ff3b34ce279 and fixed in 7.3-rc1 with commit 390f6bd8583d177029d9df4bea6667509e55a765

Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.

Unaffected versions might change over time as fixes are backported to
older supported kernel versions.  The official CVE entry at
	https://cve.org/CVERecord/?id=CVE-2026-89750
will be updated if fixes are backported, please check that for the most
up to date information about this issue.


Affected files
==============

The file(s) affected by this issue are:
	kernel/trace/trace_events_user.c


Mitigation
==========

The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes.  Individual
changes are never tested alone, but rather are part of a larger kernel
release.  Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all.  If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
	https://git.kernel.org/stable/c/63b39e49a4c9d68e010e96b26fc7374f0864f2b1
	https://git.kernel.org/stable/c/25a0758cf6bdbfddac2be71124c9bd0692f4b0b1
	https://git.kernel.org/stable/c/b799f67119aff179719a0b1e12441ebbdaaf62f9
	https://git.kernel.org/stable/c/390f6bd8583d177029d9df4bea6667509e55a765

^ permalink raw reply	[flat|nested] only message in thread

only message in thread, other threads:[~2026-09-11 20:05 UTC | newest]

Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-11 19:47 CVE-2026-89750: tracing/user_events: Clear copied tracing state before fork duplication Greg Kroah-Hartman

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.