Junglewise Threat Intelligence

CVE-2026-64173: Linux Kernel improper resource cleanup in tracing subsystem

CVE-2026-64173 · Severity: info · CVSS 0 · Published 2026-07-19

Technologies: Linux. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's tracing subsystem, which is used by developers and system administrators to monitor system performance and behavior. Under specific conditions where the system fails to allocate memory for tracing data, the kernel might attempt to improperly free resources that were never successfully created. While this is a technical error in the kernel's internal management, it could potentially lead to system instability or crashes in specific scenarios.

Technical details

A vulnerability in `kernel/trace/tracing_map.c` in the Linux kernel involves an incorrect error handling path in `tracing_map_elt_alloc()`. When the allocation of tracing map elements fails, the code incorrectly calls `map->ops->elt_free()`, despite the fact that `map->ops->elt_alloc()` was never successfully executed. This violates the expected lifecycle of the tracing map elements and can lead to undefined behavior or kernel instability. The fix introduces a internal helper function `__tracing_map_elt_free()` to ensure that the high-level free operation is only called on successfully initialized objects. This issue affects kernels from version 4.17 onwards and has been patched in multiple stable branches including 5.10.y, 5.15.y, 6.1.y, and 6.6.y.

Affected products

  • Linux Linux 4.17 to 6.14.y

Timeline

  • 2026-05-21: other: Patch authored by Masami Hiramatsu
  • 2026-07-19: disclosed: CVE published by kernel.org and NVD

References