Description
In the Linux kernel, the following vulnerability has been resolved:

tracing: Fix use-after-free in trace_pipe read on sub-buffer order change

Writing to buffer_subbuf_size_kb calls ring_buffer_subbuf_order_set(),
which frees every sub-buffer of the ring buffer, including the reader
page, and replaces them with newly allocated ones.

Readers of trace_pipe hold pointers into those pages. ring_buffer_peek()
looks up an event under cpu_buffer->reader_lock but returns the event
pointer after dropping the lock, and peek_next_entry() then calls
ring_buffer_event_length() and ring_buffer_event_data() on it. If the
sub-buffer order is changed in that window, the reader dereferences
freed memory:

BUG: KASAN: use-after-free in ring_buffer_peek+0x3e0/0x430
Read of size 1 at addr ffff88802a4cf010 by task syz-executor989/6002

Freed by:
free_buffer_page kernel/trace/ring_buffer.c:398 [inline]
ring_buffer_subbuf_order_set+0x1325/0x18e0 kernel/trace/ring_buffer.c:7444
buffer_subbuf_size_write+0x182/0x280 kernel/trace/trace.c:8221

Take trace_access_lock(RING_BUFFER_ALL_CPUS) around the order change.
This is the lock trace_pipe readers already hold across their entire
peek-and-print loop, so the swap can no longer race with a reader that
is dereferencing a peeked event.
Published: 2026-09-11
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Use‑after‑free memory corruption
Action: Patch
AI Analysis

Impact

A use‑after‑free flaw exists in the Linux kernel’s ring buffer tracing subsystem when the sub‑buffer order is changed while a reader holds a pointer into an event. The reader may dereference freed memory, potentially corrupting kernel memory or leaking sensitive data. This is a classic use‑after‑free weakness classified as CWE‑825.

Affected Systems

All hosts running a Linux kernel that lacks the patch introduced by commit 05ebe1e1d7d38c sub‑buffer reordering, are affected. The bug appears in any distribution using the affected kernel source.

Risk and Exploitability

The CVSS score of 7.8 indicates a high severity. The EPSS score of less than 1% suggests that exploitation is unlikely in the wild, and the vulnerability is not listed in CISA KEV. Attack requires a local process with write access to buffer_subbuf_size_kb to trigger the race while a trace_pipe reader is active, which typically means the attacker must have kernel or root privileges. The consistent use of a privileged operation and the nature of the race make it more of a local exploitation vector than a public remote attack.

Generated by OpenCVE AI on September 15, 2026 at 19:11 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a kernel update that incorporates the patch identified by commit 05ebe1e1d7d38c, which protects trace_pipe with trace_access_lock
  • If an update cannot be performed immediately, disable the trace subsystem by remounting‑only or unloading the trace module to eliminate the race condition until a fix is available
  • If you maintain a custom kernel, merge the specific commit that adds trace_access_lock around sub‑buffer order changes into your source and rebuild the kernel

Generated by OpenCVE AI on September 15, 2026 at 19:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.1, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H'}

cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-825
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.1, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: tracing: Fix use-after-free in trace_pipe read on sub-buffer order change Writing to buffer_subbuf_size_kb calls ring_buffer_subbuf_order_set(), which frees every sub-buffer of the ring buffer, including the reader page, and replaces them with newly allocated ones. Readers of trace_pipe hold pointers into those pages. ring_buffer_peek() looks up an event under cpu_buffer->reader_lock but returns the event pointer after dropping the lock, and peek_next_entry() then calls ring_buffer_event_length() and ring_buffer_event_data() on it. If the sub-buffer order is changed in that window, the reader dereferences freed memory: BUG: KASAN: use-after-free in ring_buffer_peek+0x3e0/0x430 Read of size 1 at addr ffff88802a4cf010 by task syz-executor989/6002 Freed by: free_buffer_page kernel/trace/ring_buffer.c:398 [inline] ring_buffer_subbuf_order_set+0x1325/0x18e0 kernel/trace/ring_buffer.c:7444 buffer_subbuf_size_write+0x182/0x280 kernel/trace/trace.c:8221 Take trace_access_lock(RING_BUFFER_ALL_CPUS) around the order change. This is the lock trace_pipe readers already hold across their entire peek-and-print loop, so the swap can no longer race with a reader that is dereferencing a peeked event.
Title tracing: Fix use-after-free in trace_pipe read on sub-buffer order change
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-13T06:33:56.494Z

Reserved: 2026-09-11T19:38:34.762Z

Link: CVE-2026-89747

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:20:05.517

Modified: 2026-09-13T07:17:39.363

Link: CVE-2026-89747

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:46:52Z

Links: CVE-2026-89747 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T19:15:16Z

Weaknesses
  • CWE-825

    Expired Pointer Dereference