CVE-2026-89746
massUse-After-Free in Linux Kernel ftrace Histogram Named Triggers
CVE-2026-89746 is a use-after-free in the Linux kernel's tracing (ftrace) subsystem: when two histogram triggers on different events are registered with the same name=, the second trigger's hist_data is freed during registration but its entry is never removed from the trace_array's hist_vars list, leaving a dangling pointer. A later hist trigger that references a variable (e.g., vals=$x) causes find_var_file() to walk that list and dereference the freed memory, triggering a KASAN slab-use-after-free and a kernel panic that can kill init. The flaw is reproducible purely from userspace by writing three hist-trigger commands to tracefs (/sys/kernel/tracing), which requires local privileged (root/CAP_SYS_ADMIN) access, consistent with the local attack vector in the CVSS 7.8 score. Any Linux kernel carrying the vulnerable event_hist_trigger_parse/hist_register_trigger code prior to the upstream fix is affected, with the primary observed impact being denial of service, though the CVSS metrics also rate high confidentiality and integrity impact. No public proof-of-concept is known and the issue is not in the CISA KEV catalog.
What to do: Update to a kernel release containing the upstream tracing fix, which removes the hist_data from tr->hist_vars and drops the trace_array reference before freeing it in the named-data branch of hist_register_trigger(). If patching is delayed, restrict or unmount tracefs (/sys/kernel/tracing) so only trusted administrators can write to event trigger files, since exploitation requires privileged local writes. Monitor for unexpected writes to /sys/kernel/tracing/events/*/trigger as an indicator of attempted triggering, and treat any unexplained kernel panics on systems with tracing enabled as suspicious.
| Linux kernel | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
In the Linux kernel, the following vulnerability has been resolved: tracing: Fix use-after-free with same-name named triggers When two hist triggers on different events are registered with the same name=, the second one reuses the first as named_data. Both are added to tr->hist_vars by save_hist_vars() during event_hist_trigger_parse(), because save_hist_vars() is called before event_trigger_register() while the named reuse is only detected later, in hist_register_trigger(). In the named-data branch hist_register_trigger() then frees the second histogram's hist_data via destroy_hist_data(), but never removes its tr->hist_vars list entry, leaving a dangling pointer and leaking the trace_array reference it holds. A later hist trigger that references a variable makes find_var_file() walk tr->hist_vars and dereference the freed hist_data. The bug is reproducible from userspace by writing three hist triggers to tracefs: cd /sys/kernel/tracing echo 'hist:keys=common_pid:x=common_pid:name=mh' > events/sched/sched_switch/trigger echo 'hist:keys=common_pid:x=common_pid:name=mh' > events/sched/sched_process_fork/trigger echo 'hist:keys=common_pid:vals=$x' > events/sched/sched_process_exit/trigger The third write panics the kernel: BUG: KASAN: slab-use-after-free in find_var_file.part.0+0x272/0x290 Read of size 8 at addr ffff888001f8a0e0 by task sh/1 CPU: 1 UID: 0 PID: 1 Comm: sh Tainted: G D N Call Trace: find_var_file.part.0 find_event_var parse_atom parse_expr __create_val_field event_hist_trigger_parse trigger_process_regex event_trigger_write vfs_write ksys_write do_syscall_64 entry_SYSCALL_64_after_hwframe Allocated by task 1: event_hist_trigger_parse Freed by task 1: hist_register_trigger+0x618/0xa30 event_hist_trigger_parse The buggy address belongs to freed 2048-byte region Oops: general protection fault ... RIP: find_var_file.part.0 Kernel panic - not syncing: Attempted to kill init! exitcode=0x0000000b Fix by removing the hist_data from tr->hist_vars and releasing the trace_array reference in the named-data branch of hist_register_trigger() before freeing the hist_data.
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.