HomeDefectsLIN1022-34255
Fixed

LIN1022-34255 : Security Advisory - linux - CVE-2026-97919

Created: Sep 25, 2026    Updated: Sep 29, 2026
Resolved Date: Sep 26, 2026
Found In Version: 10.22.33.2
Fix Version: 10.22.33.11
Severity: Standard
Applicable for: Wind River Linux LTS 22
Component/s: Kernel

Description

In the Linux kernel, the following vulnerability has been resolved:  tracing: Take the reference before publishing the named histogram trigger  event_hist_trigger_named_init() puts the trigger on the global named_triggers list and only then takes the reference on the trigger it shares its histogram with:  	data->ref++;  	save_named_trigger(data->named_data->name, data);  	ret = event_hist_trigger_init(data->named_data); 	if (ret < 0) { 		kfree(data->cmd_ops); 		data->cmd_ops = &trigger_hist_cmd; 	}  	return ret;  event_hist_trigger_init() fails when alloc_hist_pad() cannot allocate, and nothing takes the trigger back off the list on the way out. event_hist_trigger_parse() frees it, and the next lookup by name reads the freed object:   BUG: KASAN: slab-use-after-free in find_named_trigger+0xac/0xc0  Read of size 8 at addr ffff888009346860 by task init/1   find_named_trigger+0xac/0xc0   hist_register_trigger+0xc1/0xa00   event_hist_trigger_parse+0x3146/0x6af0   event_trigger_write+0xce/0x160  Freed by task 67:   kfree+0x154/0x420   trigger_kthread_fn+0xfd/0x160  Do the reference first and publish once it has succeeded, so that nothing which can fail runs after the trigger becomes findable.
Data source: kernel.org (416baaa9-dc9f-4396-8d5f-8c081fb06d67)

CVEs