Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-97921— tracing: Free histogram the field rejected for a bad modifier

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

以下是该漏洞描述信息的中文翻译: 在 Linux 内核中,已修复以下漏洞: 跟踪(tracing):释放因修饰符错误而被拒绝的直方图字段 当编写一个 hist 触发器,其值或变量携带了不允许的修饰符时,会导致为其构建的字段发生内存泄漏。 函数从 获取字段,但该字段只有在修饰符检查通过后,才会被存储在 中: 上述两个检查分支都会跳转到 标签处,而该标签在返回前没有释放任何资源。此错误处理流程会回溯到 ,后者调用 进而调用 。然而, 仅通过遍历 来访问字段。那些从未被存入 的字段将无法被访问到,从而导致泄漏。 提交 (

AI Predicted 5.5 Difficulty: Moderate EPSS 0.21% · P10

Possible ATT&CK Techniques 1 AI

T1496 · Resource Hijacking

Affected Version Matrix 17

VendorProduct Version RangeStatus
Linux Linux 7403630eb94c1d664fb873f967427ef2f6ee3699< a2652fcf96b63e9da04951e4e58e6a0672df695d affected
e30fbc618e97b38dbb49f1d44dcd0778d3f23b8c< 3d42fed18b2c5707b6332ebe87b789fd768eb01b affected
e30fbc618e97b38dbb49f1d44dcd0778d3f23b8c< e787361bb6b0026ea3eb4d3fa7a304c7fcb99555 affected
e30fbc618e97b38dbb49f1d44dcd0778d3f23b8c< b22dc0add7d72b8bd9cae3188db0dd65da1c8652 affected
e30fbc618e97b38dbb49f1d44dcd0778d3f23b8c< 891c21f6d5673b2a519b536243bfc6dd2d35beb6 affected
e30fbc618e97b38dbb49f1d44dcd0778d3f23b8c< 230234d12ce42ab04132a32c3a848f07a5d27a71 affected
8d505d06d7330f5d67d3e5e9e1c647fb0b10ddad affected
6.1.33< 6.1.189 affected
… +9 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-97921

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
tracing: Free histogram the field rejected for a bad modifier
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: tracing: Free histogram the field rejected for a bad modifier Writing a hist trigger whose value or variable carries a modifier that is not allowed there leaks the fields that were built for it. __create_val_field() takes the field from parse_expr() and stores it in hist_data->fields[] only after the modifier checks have run: hist_field = parse_expr(hist_data, file, field_str, flags, var_name, &n_subexprs); ... if (hist_field->flags & HIST_FIELD_FL_VAR) { if (hist_field->flags & (...)) goto err; } else { if (hist_field->flags & (...)) goto err; } hist_data->fields[val_idx] = hist_field; Both checks jump past that store, and the err label returns without freeing anything. The error unwinds to create_hist_data(), which calls destroy_hist_data() -> destroy_hist_fields(), and that reaches a field only by walking fields[]. A field that never got there is unreachable. commit e0213434fe3e ("tracing: Do not let histogram values have some modifiers") set ret to -EINVAL and fell through to the store, which left the field owned by fields[] and freed along with the rest of hist_data. Splitting the check into a value case and a variable case replaced that fall-through with a goto that skips it. With CONFIG_DEBUG_KMEMLEAK, 200 writes of # echo 'hist:keys=prev_pid:vals=next_pid.log2' > \ events/sched/sched_switch/trigger each correctly rejected with -EINVAL, leave 332 unreferenced objects (63744 bytes) reported at create_hist_field(); 200 install and remove cycles of a valid trigger leave none. A '.log2' field is two allocations, since create_hist_field() puts the plain field in operands[0] of the log2 field, and both are reported. Use destroy_hist_field() rather than __destroy_hist_field() so that operands[0] is freed as well. It returns early for HIST_FIELD_FL_VAR_REF, which is what an operand owned by hist_data->var_refs[] needs; the rejected field itself is never a var ref, because a var ref never carries a modifier flag.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux 7403630eb94c1d664fb873f967427ef2f6ee3699 ~ a2652fcf96b63e9da04951e4e58e6a0672df695d -
Linux Linux 6.4 -

II. Public POCs for CVE-2026-97921

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-97921

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-97921 (6)

Same Patch Batch · Linux · 2026-09-25 · 372 CVEs total

CVE-2026-100075 9.8 CRITICAL RDMA/srpt: Fix srpt_alloc_rw_ctxs() unwind counters
CVE-2026-97555 8.8 HIGH smb: client: fix heap overflow in DACL owner/group rewrite
CVE-2026-97957 8.8 HIGH net: hinic: fix mailbox segment buffer overflow
CVE-2026-97527 8.8 HIGH scsi: qla2xxx: Serialize NVMe unsol ctx list with a per-fcport lock
CVE-2026-97528 8.8 HIGH scsi: qla2xxx: Unlink NVMe unsol ctx before freeing on LS reject error
CVE-2026-98115 8.8 HIGH ksmbd: safely drain sessions during logoff
CVE-2026-97525 8.2 HIGH x86/mm/pat: Allocate split page tables as kernel page tables
CVE-2026-98069 8.1 HIGH net/rds: acquire the fastpath locks in rds_conn_shutdown()
CVE-2026-97573 8.1 HIGH bnxt_en: Handle buffer allocation failure in bnxt_rx_ring_reset()
CVE-2026-97570 8.1 HIGH bnxt_en: Bound SW TPA IDs to prevent crashes
CVE-2026-98130 8.1 HIGH sctp: fix a TOCTOU race in SCTP_CMD_TIMER_START
CVE-2026-98070 8.1 HIGH net/rds: acquire RDS_IN_XMIT in rds_tcp_reset_callbacks()
CVE-2026-98122 7.8 HIGH vxlan: mdb: Fix use-after-free in vxlan_mdb_remote_src_del()
CVE-2026-97575 7.8 HIGH media: v4l2-ctrls: validate AV1 tile counts
CVE-2026-97576 7.8 HIGH media: v4l2-ctrls: validate HEVC tile counts
CVE-2026-98112 7.8 HIGH ksmbd: fix listener task lifetime on netdev events
CVE-2026-98002 7.8 HIGH iommu/amd: Fix ineffective error check in nested domain allocation
CVE-2026-98116 7.8 HIGH ALSA: pcm: Serialize PCM mmap with buffer reallocation to fix page UAF
CVE-2026-97580 7.8 HIGH media: rkvdec: bound HEVC tile loops and PPS id to the array capacity
CVE-2026-97940 7.8 HIGH ipv6: fix fib6 walker UAF on seq stop

Showing top 20 of 372 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-97921

No comments yet


Leave a comment