Impact
The kernel bug is a use–after–free that occurs when two histogram triggers with the second trigger frees its data structure but leaves a dangling list entry, so that a subsequent trigger that references the freed data causes the kernel to dereference an invalid pointer. The result is a KASAN crash and a subsequent kernel panic, effectively bringing the system down. The weakness is classified as CWE–825.
Affected Systems
This issue affects the Linux kernel in any release prior to the inclusion of the fix that removes the stale hist_data entry and releases the trace_array reference. No specific versions are listed, so any kernel that has not yet applied the patch is potentially vulnerable.
Risk and Exploitability
The CVSS score is 7.8, indicating high severity. EPSS indicates a very low probability of exploitation (<1%), and the vulnerability is not in the CISA KEV catalog. It is inferred that the vulnerability requires a local account with write access to the /sys/kernel/tracing interface, which typically requires root. An attacker with that privilege could repeatedly crash the system, leading to a denial-of-service but not remote code execution or data theft.
OpenCVE Enrichment
Debian DSA