Executive brief
The Linux kernel's tracing subsystem includes a kprobe facility that allows dynamic instrumentation of kernel functions. A WARN_ON_ONCE() macro in the BTF parameter parsing code was triggering on legitimate user operations when adding kprobe events with raw addresses, causing unnecessary kernel warnings. The fix removes this overly strict validation check that was incorrectly flagging normal usage patterns.
Technical details
The vulnerability is a false-positive diagnostic in the parse_btf_arg() function within kernel/trace/trace_probe.c. The WARN_ON_ONCE() macro was unconditionally triggering when users attempted to create kprobe events based on raw addresses with BTF parameter information, even though this is a valid and expected use case. The fix simply removes the WARN_ON_ONCE() wrapper around the condition while retaining the error return logic, allowing the function to validate and return -EINVAL appropriately without generating spurious kernel warnings. This is a defensive programming correction rather than a security patch.
Affected products
- Linux Linux kernel 5.x, 6.x, 7.x (and later versions with the affected code)
Timeline
- 2026-08-28: disclosed: Published in NVD
- 2026-06-25: patched: Upstream fix merged by Masami Hiramatsu