Executive brief
A vulnerability was identified in the Linux kernel's fprobe component, which is used by developers and administrators to trace function calls for performance monitoring and debugging. Due to a technical error in how the system stops these traces, the kernel might attempt to use memory that has already been freed. This could lead to a system crash or unpredictable behavior, potentially impacting the stability of servers or workstations.
Technical details
A use-after-free (UAF) vulnerability exists in the Linux kernel's fprobe implementation due to a failure to wait for an RCU (Read-Copy Update) grace period during unregistration. When unregistering a probe via unregister_fprobe(), the system previously failed to call synchronize_rcu() after removing the probe from the rcu-hlist. If the memory associated with the fprobe is deallocated immediately after unregistration while a tracer is still accessing it, a UAF condition occurs. This issue primarily affects fprobe events and sample module code. The fix introduces synchronize_rcu() to ensure all RCU readers have completed before the function returns, and adds unregister_fprobe_async() for cases where asynchronous cleanup is handled elsewhere (e.g., BPF).
Affected products
- Linux Linux Kernel 6.14 to 6.18.33, 7.0.10
Timeline
- 2026-05-07: other: Patch authored
- 2026-07-19: disclosed: CVE published