Executive brief
A bug in the Linux kernel's tracing subsystem can cause a use-after-free memory error when a process with user event tracing enabled forks and the child process fails during initialization. This could allow a local attacker to crash the kernel or potentially execute arbitrary code with kernel privileges, affecting system stability and security.
Technical details
A use-after-free vulnerability exists in the kernel tracing subsystem (kernel/trace/trace_events_user.c). When a process with user_event_mm (tracing state) forks, dup_task_struct() copies the parent's user_event_mm pointer to the child without incrementing its reference count. The user_event_mm_dup() function is supposed to allocate a new structure for the child, but if user_event_mm_alloc() fails, the function leaves the copied pointer intact. When the child process exits, user_event_mm_remove() decrements a reference the child never owned, freeing the structure while the parent still holds a stale pointer. Subsequent access by the parent triggers a use-after-free. Exploitation requires local access and a process with tracing enabled that attempts to fork; no special privileges are required. The fix clears the copied pointer before any possible failure, ensuring only actual allocations are freed.
Affected products
- Linux Linux Kernel multiple versions (detailed version range not specified in advisory)
Timeline
- 2026-09-11: disclosed
- 2026-08-27: patched: Fix commit 390f6bd8583d177029d9df4bea6667509e55a765