Executive brief
The Linux kernel's UFS (Ultra Disk Format) driver contains a use-after-free vulnerability in its tracing code. When kernel tracing events are read from the trace file (potentially minutes, hours, or days after the event occurred), the code attempts to dereference a pointer that may have been freed in the interim, causing a kernel crash. This impacts system stability and availability on systems using UFS and kernel tracing.
Technical details
The vulnerability exists in the UFS core tracing module (drivers/ufs/core/ufs_trace.h) where TP_printk() macros attempted to dereference an hba (host bus adapter) structure pointer stored in the trace ring buffer. The root cause is that TP_printk() executes when trace data is read from /sys/kernel/tracing/trace, which can occur arbitrarily long after the tracepoint was triggered—at which time the original hba structure may have been deallocated. The fix captures the device name string at tracepoint trigger time and stores it directly in the ring buffer, eliminating the deference of potentially stale pointers. The vulnerability affects multiple trace events in the UFS driver and was detected via systematic testing of TP_printk() parameter dereferencing.
Affected products
- Linux Linux kernel Multiple versions (fixed in 535fcf4b8a261fbb8cc4f91e4597343c135a90f2)
Timeline
- 2026-08-28: disclosed
- 2026-07-07: patched: Upstream fix committed 2026-06-30, backported to stable