CVE-2026-97920
Received Received - Intake

Integer Overflow in Linux Kernel Tracing Histogram

Vulnerability report for CVE-2026-97920, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-25

Last updated on: 2026-09-25

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: tracing: Keep the entry count when the histogram stats allocation fails print_entries() uses n_entries both as the number of sort entries and as its own return value, so the -ENOMEM it stores when the stats allocation fails overwrites the count that the cleanup still needs: n_entries = tracing_map_sort_entries(map, ...); if (n_entries < 0) return n_entries; ... if (!stats) { n_entries = -ENOMEM; goto out; } ... out: tracing_map_destroy_sort_entries(sort_entries, n_entries); tracing_map_destroy_sort_entries() takes an unsigned int and loops up to it, so -ENOMEM arrives as 4294967284. It walks an array of at most map->max_elts pointers and calls destroy_sort_entry(), which dereferences and frees, on whatever lies past the end. Reading the hist file of a trigger with a .percent value, with that allocation forced to fail: BUG: KASAN: vmalloc-out-of-bounds in tracing_map_destroy_sort_entries+0xa0/0xb0 Read of size 8 at addr ffffc90000045000 by task init/1 tracing_map_destroy_sort_entries+0xa0/0xb0 hist_show+0x6f7/0x1df0 seq_read_iter+0x2b8/0x1190 vfs_read+0x176/0xa40 The buggy address belongs to a 4-page vmalloc region starting at ffffc90000041000 allocated at tracing_map_sort_entries+0x5c/0xd50 A few pages further the fault is fatal. The registers at the oops confirm the bound: the loop's end pointer less the array start, over the pointer size, is 4294967284. Return the error in a separate variable and leave n_entries holding the count, the way tracing_map_sort_entries() does on its own error path. The stats block is only entered for a value carrying .percent or .graph, which __create_val_field() has rejected since v6.3, so this cannot be reached in mainline as it stands. It becomes reachable again with "tracing: hist: let values keep the percent and graph modifiers", so it should be applied first.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-25
Last Modified
2026-09-25
Generated
2026-09-25
AI Q&A
2026-09-25
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
linux linux_kernel *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a Linux kernel vulnerability where an error handling flaw in the tracing subsystem leads to a memory out-of-bounds read. When histogram stats allocation fails, the error code overwrites a counter variable, causing it to become a large positive number instead of a negative error value. This leads to an invalid memory access when cleaning up trace entries.

Detection Guidance

This vulnerability is specific to the Linux kernel's tracing subsystem and may not have direct network detection methods. Monitor kernel logs for KASAN out-of-bounds errors or crashes related to tracing_map_destroy_sort_entries. Check for abnormal behavior when reading histogram files with .percent or .graph values.

Impact Analysis

This vulnerability could cause a kernel crash (oops) or system instability if exploited. An attacker with local access might trigger it by reading specific trace files, leading to a denial of service. The impact is limited to systems using kernel tracing features with histogram triggers.

Mitigation Strategies

Apply the Linux kernel patch that fixes this issue. Update to a patched kernel version where the error handling in tracing_map_destroy_sort_entries is corrected. Avoid using histogram triggers with .percent or .graph values until patched.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-97920. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart