Description
In the Linux kernel, the following vulnerability has been resolved:

tracing/user_events: Clear copied tracing state before fork duplication

dup_task_struct() copies user_event_mm from the parent into the child,
without grabbing a reference to it. user_event_mm_dup() should
replace it, but it leaves that copied pointer unmodified if
user_event_mm_alloc() fails.

When the child exits, user_event_mm_remove() decrements a reference
the child never owned, which ultimately frees user_event_mm, while
the parent still as a stale pointer to it. This creates a UAF, which
KASAN reports as:

BUG: KASAN: slab-use-after-free in
current_user_event_mm+0x51/0x1d0 Write of size 4 at addr
ffff888005010d30 by task init/44

Call Trace:
<TASK>
kasan_report+0xce/0x100
kasan_check_range+0x10f/0x1e0
current_user_event_mm+0x51/0x1d0
user_events_ioctl+0x82e/0x15c0
__x64_sys_ioctl+0x139/0x1c0
do_syscall_64+0xce/0x450
entry_SYSCALL_64_after_hwframe+0x77/0x7f

Allocated by task 44:
__kasan_kmalloc+0x8f/0xa0
__kmalloc_cache_noprof+0x180/0x3a0
user_event_mm_alloc+0x3c/0x1f0
current_user_event_mm+0x88/0x1d0

Freed by task 42:
__kasan_slab_free+0x43/0x70
kfree+0x13a/0x390
process_one_work+0x696/0xf90
worker_thread+0x420/0xba0

The fix simply clears the copied pointer before any possible failure.
In case of failure, the child then has nothing to free.
Published: 2026-09-11
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Use-After‑Free in kernel memory
Action: Apply Patch
AI Analysis

Impact

The vulnerability stems from the Linux kernel’s tracing/user_events subsystem, where the dup_task_struct() function copies a pointer to a user event memory region into the child process without incrementing a reference count. If the subsequent allocation of that region fails, the child leaves the pointer unchanged. When the child exits, its cleanup routine frees the region it never owned, leaving the parent with a stale reference. This use‑after‑free can corrupt kernel memory, as observed by KASAN reports, and is classified as CWE‑825.

Affected Systems

Any Linux kernel build that includes the legacy tracing/user_events implementation prior to the upstream patch is affected. The CNA lists the product as Linux:Linux with no specific version range, so all kernels lacking the fix are considered vulnerable until updated. Systems running kernels with the tracing subsystem enabled and exposed to the relevant ioctl calls that allocate user events are at risk.

Risk and Exploitability

With a CVSS score of 7.8 the vulnerability is high. The EPSS score of <1% indicates a very low but non‑zero probability of exploitation. It is not listed in CISA’s KEV catalog. Local; an attacker must be able to fork a process or trigger the ioctl sequence that allocates the allocation failure or make the child exit while the parent still has the stale pointer. Successful exploitation could lead to kernel memory corruption and privilege escalation. The low EPSS suggests limited active exploitation currently.

Generated by OpenCVE AI on September 15, 2026 at 19:10 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to any release that incorporates the tracing/user_events patch from upstream.
  • If a full kernel upgrade is not feasible, apply the vendor‑provided kernel update that contains the fix.
  • Disable the user event subsystem by unsetting the relevant sysctl(s) or removing the module that exposes the ioctl interfaces, thereby preventing the allocation of user event memory.
  • Monitor system logs for KASAN messages that indicate use‑after‑free, and restrict access to the ioctl calls that interact with user events.

Generated by OpenCVE AI on September 15, 2026 at 19:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 14 Sep 2026 12:30:00 +0000


Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H'}

cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-825
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: tracing/user_events: Clear copied tracing state before fork duplication dup_task_struct() copies user_event_mm from the parent into the child, without grabbing a reference to it. user_event_mm_dup() should replace it, but it leaves that copied pointer unmodified if user_event_mm_alloc() fails. When the child exits, user_event_mm_remove() decrements a reference the child never owned, which ultimately frees user_event_mm, while the parent still as a stale pointer to it. This creates a UAF, which KASAN reports as: BUG: KASAN: slab-use-after-free in current_user_event_mm+0x51/0x1d0 Write of size 4 at addr ffff888005010d30 by task init/44 Call Trace: <TASK> kasan_report+0xce/0x100 kasan_check_range+0x10f/0x1e0 current_user_event_mm+0x51/0x1d0 user_events_ioctl+0x82e/0x15c0 __x64_sys_ioctl+0x139/0x1c0 do_syscall_64+0xce/0x450 entry_SYSCALL_64_after_hwframe+0x77/0x7f Allocated by task 44: __kasan_kmalloc+0x8f/0xa0 __kmalloc_cache_noprof+0x180/0x3a0 user_event_mm_alloc+0x3c/0x1f0 current_user_event_mm+0x88/0x1d0 Freed by task 42: __kasan_slab_free+0x43/0x70 kfree+0x13a/0x390 process_one_work+0x696/0xf90 worker_thread+0x420/0xba0 The fix simply clears the copied pointer before any possible failure. In case of failure, the child then has nothing to free.
Title tracing/user_events: Clear copied tracing state before fork duplication
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-14T12:02:29.948Z

Reserved: 2026-09-11T19:38:34.762Z

Link: CVE-2026-89750

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:20:05.883

Modified: 2026-09-14T13:19:23.640

Link: CVE-2026-89750

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:46:54Z

Links: CVE-2026-89750 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T19:15:16Z

Weaknesses
  • CWE-825

    Expired Pointer Dereference