目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2026-97921— Tracing 组件因无效修饰符导致拒绝字段被释放漏洞

一分钟漏洞结论

影响对象
Linux Linux
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

以下是该漏洞描述信息的中文翻译: 在 Linux 内核中,已修复以下漏洞: 跟踪(tracing):释放因修饰符错误而被拒绝的直方图字段 当编写一个 hist 触发器,其值或变量携带了不允许的修饰符时,会导致为其构建的字段发生内存泄漏。 函数从 获取字段,但该字段只有在修饰符检查通过后,才会被存储在 中: 上述两个检查分支都会跳转到 标签处,而该标签在返回前没有释放任何资源。此错误处理流程会回溯到 ,后者调用 进而调用 。然而, 仅通过遍历 来访问字段。那些从未被存入 的字段将无法被访问到,从而导致泄漏。 提交 (

AI 预测 5.5 利用难度: 中等 EPSS 0.21% · P10

可能的 ATT&CK 技术 1 AI

T1496 · Resource Hijacking

影响版本矩阵 17

厂商产品 版本范围状态
Linux Linux 7403630eb94c1d664fb873f967427ef2f6ee3699< a2652fcf96b63e9da04951e4e58e6a0672df695d affected
e30fbc618e97b38dbb49f1d44dcd0778d3f23b8c< 3d42fed18b2c5707b6332ebe87b789fd768eb01b affected
e30fbc618e97b38dbb49f1d44dcd0778d3f23b8c< e787361bb6b0026ea3eb4d3fa7a304c7fcb99555 affected
e30fbc618e97b38dbb49f1d44dcd0778d3f23b8c< b22dc0add7d72b8bd9cae3188db0dd65da1c8652 affected
e30fbc618e97b38dbb49f1d44dcd0778d3f23b8c< 891c21f6d5673b2a519b536243bfc6dd2d35beb6 affected
e30fbc618e97b38dbb49f1d44dcd0778d3f23b8c< 230234d12ce42ab04132a32c3a848f07a5d27a71 affected
8d505d06d7330f5d67d3e5e9e1c647fb0b10ddad affected
6.1.33< 6.1.189 affected
… +9 条更多
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2026-97921 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
tracing: Free histogram the field rejected for a bad modifier
来源: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: tracing: Free histogram the field rejected for a bad modifier Writing a hist trigger whose value or variable carries a modifier that is not allowed there leaks the fields that were built for it. __create_val_field() takes the field from parse_expr() and stores it in hist_data->fields[] only after the modifier checks have run: hist_field = parse_expr(hist_data, file, field_str, flags, var_name, &n_subexprs); ... if (hist_field->flags & HIST_FIELD_FL_VAR) { if (hist_field->flags & (...)) goto err; } else { if (hist_field->flags & (...)) goto err; } hist_data->fields[val_idx] = hist_field; Both checks jump past that store, and the err label returns without freeing anything. The error unwinds to create_hist_data(), which calls destroy_hist_data() -> destroy_hist_fields(), and that reaches a field only by walking fields[]. A field that never got there is unreachable. commit e0213434fe3e ("tracing: Do not let histogram values have some modifiers") set ret to -EINVAL and fell through to the store, which left the field owned by fields[] and freed along with the rest of hist_data. Splitting the check into a value case and a variable case replaced that fall-through with a goto that skips it. With CONFIG_DEBUG_KMEMLEAK, 200 writes of # echo 'hist:keys=prev_pid:vals=next_pid.log2' > \ events/sched/sched_switch/trigger each correctly rejected with -EINVAL, leave 332 unreferenced objects (63744 bytes) reported at create_hist_field(); 200 install and remove cycles of a valid trigger leave none. A '.log2' field is two allocations, since create_hist_field() puts the plain field in operands[0] of the log2 field, and both are reported. Use destroy_hist_field() rather than __destroy_hist_field() so that operands[0] is freed as well. It returns early for HIST_FIELD_FL_VAR_REF, which is what an operand owned by hist_data->var_refs[] needs; the rejected field itself is never a var ref, because a var ref never carries a modifier flag.
来源: CVE Program / CVE List V5
CVSS Information
N/A
来源: CVE Program / CVE List V5
Vulnerability Type
N/A
来源: CVE Program / CVE List V5

受影响产品

厂商 产品 影响版本 CPE 订阅
Linux Linux 7403630eb94c1d664fb873f967427ef2f6ee3699 ~ a2652fcf96b63e9da04951e4e58e6a0672df695d -
Linux Linux 6.4 -

二、漏洞 CVE-2026-97921 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-97921 的情报信息

请登录查看更多情报信息。

CVE-2026-97921 补丁与修复 (6)

同批安全公告 · Linux · 2026-09-25 · 共 372 条

CVE-2026-100075 9.8 CRITICAL RDMA/srpt:srpt_alloc_rw_ctxs() 未释放计数器修复
CVE-2026-97555 8.8 HIGH smb客户端:修复DACL所有者/组重写中的堆溢出漏洞
CVE-2026-97957 8.8 HIGH hinic 邮箱段缓冲区溢出漏洞
CVE-2026-97527 8.8 HIGH qla2xxx SCSI驱动程序 NVMe未解决上下文列表竞争条件漏洞
CVE-2026-97528 8.8 HIGH QLogic qla2xxx驱动LS拒绝错误NVMe内存泄漏漏洞
CVE-2026-98115 8.8 HIGH ksmbd 注销期间会话安全排空漏洞
CVE-2026-97525 8.2 HIGH x86/mm/pat:内核页表分裂页表分配漏洞
CVE-2026-98069 8.1 HIGH Net/RDS rds_conn_shutdown() 快速路径锁获取漏洞
CVE-2026-97573 8.1 HIGH bnxt_en 驱动 bnxt_rx_ring_reset 缓冲区分配失败漏洞
CVE-2026-97570 8.1 HIGH bnxt_en: 修复因SW TPA ID绑定问题导致的崩溃漏洞
CVE-2026-98130 8.1 HIGH SCTP定时器启动竞争条件漏洞
CVE-2026-98070 8.1 HIGH Linux RDS 模块远程代码执行漏洞
CVE-2026-98122 7.8 HIGH Linux内核vxlan mdb远程源删除后使用漏洞
CVE-2026-97575 7.8 HIGH v4l2-ctrls AV1瓦片计数验证漏洞
CVE-2026-97576 7.8 HIGH V4L2-ctrls HEVC 瓦片计数验证漏洞
CVE-2026-98112 7.8 HIGH ksmbd 网络接口事件中监听器任务生命周期修复漏洞
CVE-2026-98002 7.8 HIGH AMD IOMMU 嵌套域分配中错误检查失效漏洞
CVE-2026-98116 7.8 HIGH ALSA: PCM内存映射与缓冲区重新分配序列化以修复页面UAF漏洞
CVE-2026-97580 7.8 HIGH rkvdec HEVC解析数组越界漏洞
CVE-2026-97940 7.8 HIGH IPv6 修复 fib6 遍历器在 seq 停止时存在 UAF 漏洞

显示前 20 条,共 372 条。 查看全部 &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-97921

暂无评论


发表评论