Description
In the Linux kernel, the following vulnerability has been resolved:

tracing: Take trace_array reference when opening options file

The options files do not take the trace_array reference for the options
they represent. This could cause a use-after-free kernel crash if one of
these files is opened by one task and another task removes the instance
that the option is for. Because it doesn't take a reference upon opening,
it will not stop the removal which will free the options descriptor that
is being used.

As the options are somewhat dynamic in their creation at boot up, each
file represents a flag in the trace_array. The trace_array has an array of
indexes to represent each of these flags that is stored in the
trace_flags_index array. The address of the index array element is used to
pass to the inode->i_private pointer. Then that element is read which
holds the index (which represents the flag) and then the index is used to
calculate the trace_array descriptor from its trace_flags_index array.

One issue is that the index element can not be referenced until the
trace_array's reference is taken. To handle this, create a new helper
function called: trace_array_options_get() that will iterate all the
existing trace_arrays in the ftrace_trace_arrays list (under the
trace_types_lock), and compare the passed in address of the index element
with the entire array of the trace_array's trace_flags_index array.
If it matches, then up the corresponding trace_array's reference and
return.
Published: 2026-09-16
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Kernel Crash (Denial of Service)
Action: Patch Update
AI Analysis

Impact

The Linux kernel contains a defect where the tracing subsystem does not acquire a reference on the trace_array object when an options file is opened. If a second task removes that trace instance while the options file remains open, the freed trace_array descriptor is still accessed, causing a use‑after‑free crash in kernel space. The primary impact is a kernel panic that takes the system offline. Based on the description, the attack requires local access and concurrent operations; no remote code execution capability is specified, so it represents a local denial‑of‑service scenario.

Affected Systems

All Linux kernel releases that expose ftrace options files without correctly referencing trace arrays are affected, as the issue resides in the core ftrace module. The vulnerability applies to every kernel version before the patch that introduces trace_array_options_get(); affected vendor is Linux.

Risk and Exploitability

Scored CVSS 7.8, indicating high severity. The EPSS measurement is less than 1 %, signaling a very low proven exploitation probability. The flaw is not listed in CISA’s KEV catalog. The likely attack vector is local, requiring a user to open an ftrace option file while another user or process removes the corresponding trace array. Though exploitation is unlikely in the wild, the potential for a kernel crash warrants timely patching.

Generated by OpenCVE AI on September 18, 2026 at 07:09 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a kernel update that includes the trace_array reference acquisition through trace_array_options_get().
  • If an immediate upgrade is not possible, remove or disable the ftrace options files so that no trace instance files are accessed after the trace array has been removed.
  • Monitor system logs for Oops or panic messages related to ftrace; if such logs appear, reboot the affected system to restore service.
  • Temporarily disable ftrace features by setting /proc/sys/kernel/ftrace_enabled=0 to eliminate the exploitation path until a patch is available.

Generated by OpenCVE AI on September 18, 2026 at 07:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 03 Oct 2026 11:15:00 +0000


Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: tracing: Take trace_array reference when opening options file The options files do not take the trace_array reference for the options they represent. This could cause a use-after-free kernel crash if one of these files is opened by one task and another task removes the instance that the option is for. Because it doesn't take a reference upon opening, it will not stop the removal which will free the options descriptor that is being used. As the options are somewhat dynamic in their creation at boot up, each file represents a flag in the trace_array. The trace_array has an array of indexes to represent each of these flags that is stored in the trace_flags_index array. The address of the index array element is used to pass to the inode->i_private pointer. Then that element is read which holds the index (which represents the flag) and then the index is used to calculate the trace_array descriptor from its trace_flags_index array. One issue is that the index element can not be referenced until the trace_array's reference is taken. To handle this, create a new helper function called: trace_array_options_get() that will iterate all the existing trace_arrays in the ftrace_trace_arrays list (under the trace_types_lock), and compare the passed in address of the index element with the entire array of the trace_array's trace_flags_index array. If it matches, then up the corresponding trace_array's reference and return.
Title tracing: Take trace_array reference when opening options file
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-10-03T10:56:58.061Z

Reserved: 2026-09-11T19:38:34.781Z

Link: CVE-2026-90013

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:17:13.997

Modified: 2026-10-03T11:17:45.557

Link: CVE-2026-90013

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T07:15:04Z

Weaknesses

No weakness.