目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2026-98076— tracing/probes: 修复多探针事件字段名称/类型的用后释放漏洞

一分钟漏洞结论

影响对象
Linux Linux
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

在 Linux 内核中,已解决以下漏洞: tracing/probes:修复具有多个探测点的动态事件字段名称/类型中的释放后使用(use-after-free)问题 基于探测的动态事件(kprobe、uprobe、eprobe 和 fprobe 事件)的字段是在 函数中创建的,该方法将 的名称/类型字符串指针传递给 。 仅存储这些指针而不进行复制。这些字符串由 拥有,并在该探测点被移除时释放。 一个事件可以附加多个探测点。字段列表仅由第一个注册该事件的探测点定义一次,但只要有任何幸存的兄弟探测点存在,该字段列表就会

AI 预测 6.5 利用难度: 较易 EPSS 0.21% · P10

影响版本矩阵 18

厂商产品 版本范围状态
Linux Linux ca89bc071d5e4e981dcc52e0ca90f4500d332e42< 38305e1b8b1ec27eef8f2d4e461e3b6c8624d494 affected
ca89bc071d5e4e981dcc52e0ca90f4500d332e42< 6d6118c17bc791594cbfd9cc4936ee21073b894a affected
ca89bc071d5e4e981dcc52e0ca90f4500d332e42< a2510fcaad92b09b34574c97e8356234c6a84a9a affected
ca89bc071d5e4e981dcc52e0ca90f4500d332e42< 9379e193826f23876daccb3351fab89c87084ba3 affected
ca89bc071d5e4e981dcc52e0ca90f4500d332e42< 68ae584169c7a41fc9bc4677c1d368983cf44b21 affected
ca89bc071d5e4e981dcc52e0ca90f4500d332e42< 411c9080a776577664531b4f7d3ee53b7a747ba8 affected
ca89bc071d5e4e981dcc52e0ca90f4500d332e42< 178ff2e011e21fbebdf57f5d58a408fe59136d82 affected
ca89bc071d5e4e981dcc52e0ca90f4500d332e42< 86b7a239ec6b14a7544200ede85474c6f5526049 affected
… +10 条更多
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2026-98076 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
tracing/probes: Fix use-after-free on field name/type of events with multiple probes
来源: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: tracing/probes: Fix use-after-free on field name/type of events with multiple probes The fields of a probe-based dynamic event (kprobe, uprobe, eprobe and fprobe events) are created in traceprobe_define_arg_fields() by handing the probe_arg name/type strings to trace_define_field(), which only stores the pointers without copying. Those strings are owned by the trace_probe and are freed when that probe is removed. An event can have several probes attached. The field list is defined only once, by the first probe that registers the event, but it is kept alive by any surviving sibling probe. Deleting just that first probe by symbol - # primary A: fields are defined from A's args echo 'p:kprobes/ev vfs_read a1=$arg1' > kprobe_events # append B: shares A's event call echo 'p:kprobes/ev vfs_write a1=$arg1' >> kprobe_events # delete only A (matched by symbol), B survives echo '-:kprobes/ev vfs_read' >> kprobe_events frees A's args (trace_probe_cleanup() -> traceprobe_free_probe_arg()), but trace_probe_unlink() keeps the trace_probe_event because the probe list is not empty. The event call stays registered via B while its fields now reference freed memory. Any field lookup then reads it, e.g. echo 'a1 == 1' > events/kprobes/ev/filter BUG: KASAN: slab-use-after-free in strcmp+0xa7/0xb0 Call Trace: strcmp trace_find_event_field parse_pred process_preds create_filter apply_event_filter event_filter_write field->name references parg->name (kstrdup'd, freed with the probe) and, for array arguments, field->type references parg->fmt (kmalloc'd, freed with the probe) - the scalar type otherwise points at the static fmttype rodata, which is safe. Have traceprobe_define_arg_fields() duplicate the name and type strings and anchor the copies on the trace_probe_event, which embeds the event call and outlives every individual probe; trace_probe_event_free() releases them. The reproducer above triggers reliably; the field lookup and the delete both run under event_mutex, so this is a dangling reference after removal rather than a race. The issue was found by the autokbug dynamic kernel fuzzer at Tencent Yunding Lab.
来源: CVE Program / CVE List V5
CVSS Information
N/A
来源: CVE Program / CVE List V5
Vulnerability Type
N/A
来源: CVE Program / CVE List V5

受影响产品

厂商 产品 影响版本 CPE 订阅
Linux Linux ca89bc071d5e4e981dcc52e0ca90f4500d332e42 ~ 38305e1b8b1ec27eef8f2d4e461e3b6c8624d494 -
Linux Linux 5.4 -

二、漏洞 CVE-2026-98076 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-98076 的情报信息

请登录查看更多情报信息。

CVE-2026-98076 补丁与修复 (8)

同批安全公告 · Linux · 2026-09-25 · 共 372 条

CVE-2026-100075 9.8 CRITICAL RDMA/srpt:srpt_alloc_rw_ctxs() 未释放计数器修复
CVE-2026-97555 8.8 HIGH smb客户端:修复DACL所有者/组重写中的堆溢出漏洞
CVE-2026-97957 8.8 HIGH hinic 邮箱段缓冲区溢出漏洞
CVE-2026-97527 8.8 HIGH qla2xxx SCSI驱动程序 NVMe未解决上下文列表竞争条件漏洞
CVE-2026-97528 8.8 HIGH QLogic qla2xxx驱动LS拒绝错误NVMe内存泄漏漏洞
CVE-2026-98115 8.8 HIGH ksmbd 注销期间会话安全排空漏洞
CVE-2026-97525 8.2 HIGH x86/mm/pat:内核页表分裂页表分配漏洞
CVE-2026-98069 8.1 HIGH Net/RDS rds_conn_shutdown() 快速路径锁获取漏洞
CVE-2026-97573 8.1 HIGH bnxt_en 驱动 bnxt_rx_ring_reset 缓冲区分配失败漏洞
CVE-2026-97570 8.1 HIGH bnxt_en: 修复因SW TPA ID绑定问题导致的崩溃漏洞
CVE-2026-98130 8.1 HIGH SCTP定时器启动竞争条件漏洞
CVE-2026-98070 8.1 HIGH Linux RDS 模块远程代码执行漏洞
CVE-2026-98002 7.8 HIGH AMD IOMMU 嵌套域分配中错误检查失效漏洞
CVE-2026-97575 7.8 HIGH v4l2-ctrls AV1瓦片计数验证漏洞
CVE-2026-97576 7.8 HIGH V4L2-ctrls HEVC 瓦片计数验证漏洞
CVE-2026-97941 7.8 HIGH Linux 内核 slab 内存分配器竞态条件漏洞
CVE-2026-98112 7.8 HIGH ksmbd 网络接口事件中监听器任务生命周期修复漏洞
CVE-2026-97937 7.8 HIGH Linux内核ftrace远程代码执行漏洞
CVE-2026-97580 7.8 HIGH rkvdec HEVC解析数组越界漏洞
CVE-2026-97940 7.8 HIGH IPv6 修复 fib6 遍历器在 seq 停止时存在 UAF 漏洞

显示前 20 条,共 372 条。 查看全部 &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-98076

暂无评论


发表评论