CVE-2026-97936
Received Received - Intake

Memory Corruption in Linux Kernel Histogram Stacktrace

Vulnerability report for CVE-2026-97936, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-25

Last updated on: 2026-09-25

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: tracing: Fix memory corruption from the histogram stacktrace modifier parse_field() sets HIST_FIELD_FL_STACKTRACE from the ".stacktrace" modifier before it looks the field name up, and nothing afterwards checks that the name resolved to a field which holds a stacktrace. create_hist_field() picks HIST_FIELD_FN_STACK on the strength of the field pointer alone, which reads a __data_loc word from the record and follows its low 16 bits as an offset into the same record. event_hist_trigger() takes the first word there as an entry count and copies that many longs into a 31 entry array: n_entries = *stack; memcpy(entries, ++stack, n_entries * sizeof(unsigned long)); Neither end of that copy is bounded, and the count is whatever the event holds at the offset, so any field will do: # cd /sys/kernel/tracing/events/sched/sched_process_fork # echo 'hist:keys=parent_pid.stacktrace' > trigger # (true) BUG: kernel NULL pointer dereference, address: 0000000000000008 RIP: 0010:rb_insert_color+0x18/0x130 timerqueue_linked_add+0x7e/0xd0 enqueue_hrtimer+0x39/0xb0 __hrtimer_run_queues+0x10f/0x1f0 </IRQ> RIP: 0010:memcpy+0xc/0x30 event_hist_trigger+0x165/0x690 The timer interrupt landed on the rbtree the copy had already run over. No debug options are needed for this; KASAN reports the same write as an out-of-bounds read of 13835058055416381440 bytes. Documentation/trace/histogram.rst already states the rule, "must be a long[] type", so enforce it once the name has been resolved. Names which resolve to no field at all, "hitcount.stacktrace" and the common_* pseudo-fields, are refused for the same reason: they hold no stacktrace to read.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-25
Last Modified
2026-09-25
Generated
2026-09-25
AI Q&A
2026-09-25
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
linux linux_kernel *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Linux kernel involves memory corruption caused by improper handling of stacktrace modifiers in histogram fields. The issue occurs when parse_field() sets a stacktrace flag before verifying the field name, leading to incorrect memory access. create_hist_field() then uses this flag to read untrusted data, causing a buffer overflow when copying stacktrace entries. This can result in kernel crashes or other undefined behavior.

Detection Guidance

This vulnerability can be detected by checking for the presence of the histogram stacktrace modifier in the Linux kernel's tracing subsystem. Look for commands or configurations that use '.stacktrace' in histogram triggers, such as 'echo hist:keys=parent_pid.stacktrace > trigger' in /sys/kernel/tracing/events/sched/sched_process_fork.

Impact Analysis

This vulnerability could allow local attackers to cause a kernel crash or execute arbitrary code with elevated privileges. It may lead to denial-of-service conditions, system instability, or potential privilege escalation if exploited. Users running vulnerable Linux kernel versions with tracing enabled could be affected.

Mitigation Strategies

Apply the latest Linux kernel patches that address this issue. Avoid using the '.stacktrace' modifier in histogram triggers until a patched kernel is installed. Monitor kernel logs for NULL pointer dereference errors or KASAN reports indicating out-of-bounds memory access.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-97936. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart