Description
In the Linux kernel, the following vulnerability has been resolved:

kprobes: Protect kprobe_blacklist with RCU

__within_kprobe_blacklist() traverses kprobe_blacklist without holding
kprobe_mutex. When a module is unloaded, kprobe_remove_area_blacklist()
removes blacklist entries and immediately frees them with kfree().
A concurrent call to within_kprobe_blacklist() can therefore dereference
freed memory.

Furthermore, within_kprobe_blacklist() can be called in atomic or
non-preemptible contexts where the sleeping kprobe_mutex cannot be taken.

Protect kprobe_blacklist with RCU. Use guard(rcu)() and
list_for_each_entry_rcu() for traversal, list_add_tail_rcu() for
insertions, list_del_rcu() for deletions, and kfree_rcu() to reclaim
entries safely after a grace period.
Published: 2026-09-16
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation via Kernel Corruption
Action: Apply Patch
AI Analysis

Impact

A use‑after‑free condition exists in the Linux kernel kprobe subsystem when the blacklist list is walked without holding the kprobe_mutex lock. During module unload, blacklist entries are removed and freed with kfree, but a concurrent traversal may dereference the freed memory, corrupting kernel structures and potentially allowing an attacker to execute arbitrary code with kernel privileges.

Affected Systems

The flaw affects the Linux kernel in general; any kernel lacking the RCU protection commit for kprobe_blacklist is vulnerable. No specific version range is listed, so a review of release notes for the RCU‑based patch is required to confirm whether a deployment is affected.

Risk and Exploitability

With a CVSS score of 7.8 the vulnerability is deemed high severity. The EPSS score of less than 1% indicates a very low current likelihood of exploitation, and it is not listed in the CISA KEV catalog. Based on the description, the attack vector is local, requiring an actor capable of loading or unloading kernel modules. Exploitation would depend on precise timing of probe activity and module unloading to trigger the use‑after‑free during a concurrent kprobe traversal.

Generated by OpenCVE AI on September 18, 2026 at 07:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a Linux kernel version that includes the RCU protection for kprobe_blacklist.
  • If an update cannot be applied immediately, avoid unloading kernel modules while probes are active to eliminate concurrent access to the blacklist.
  • Restart the system to clear any pending probe operations and ensure a safe kernel state.

Generated by OpenCVE AI on September 18, 2026 at 07:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: kprobes: Protect kprobe_blacklist with RCU __within_kprobe_blacklist() traverses kprobe_blacklist without holding kprobe_mutex. When a module is unloaded, kprobe_remove_area_blacklist() removes blacklist entries and immediately frees them with kfree(). A concurrent call to within_kprobe_blacklist() can therefore dereference freed memory. Furthermore, within_kprobe_blacklist() can be called in atomic or non-preemptible contexts where the sleeping kprobe_mutex cannot be taken. Protect kprobe_blacklist with RCU. Use guard(rcu)() and list_for_each_entry_rcu() for traversal, list_add_tail_rcu() for insertions, list_del_rcu() for deletions, and kfree_rcu() to reclaim entries safely after a grace period.
Title kprobes: Protect kprobe_blacklist with RCU
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T14:41:04.007Z

Reserved: 2026-09-11T19:38:34.779Z

Link: CVE-2026-89988

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:17:09.890

Modified: 2026-09-16T15:18:22.680

Link: CVE-2026-89988

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T07:30:05Z

Weaknesses

No weakness.