Executive brief
The Linux kernel's mmiotrace feature (a performance tracing tool for memory-mapped I/O operations) can crash if logging functions are called before the tracer is fully initialized or after it has been disabled. This causes a kernel panic that disrupts system availability and can trigger a reboot.
Technical details
The vulnerability is a NULL pointer dereference in kernel/trace/trace_mmiotrace.c. The functions __trace_mmiotrace_rw() and __trace_mmiotrace_map() directly dereference the mmio_trace_array pointer (retrieved as variable tr) to access tr->array_buffer.buffer without first verifying it is not NULL. If these functions are invoked during module initialization or after mmiotrace is disabled, mmio_trace_array will be NULL, causing a kernel crash. The fix adds an explicit NULL check at the beginning of both functions to gracefully return early if tr is NULL. No authentication or special privilege is required; the condition can occur during normal system operation or through userspace tracing operations.
Affected products
- Linux Linux kernel 2.6.11 and later (all tracked stable versions)
Timeline
- 2026-08-28: disclosed
- 2026-07-29: patched: fix committed upstream by Steven Rostedt