Impact
The Linux kernel contains a defect where the tracing subsystem does not acquire a reference on the trace_array object when an options file is opened. If a second task removes that trace instance while the options file remains open, the freed trace_array descriptor is still accessed, causing a use‑after‑free crash in kernel space. The primary impact is a kernel panic that takes the system offline. Based on the description, the attack requires local access and concurrent operations; no remote code execution capability is specified, so it represents a local denial‑of‑service scenario.
Affected Systems
All Linux kernel releases that expose ftrace options files without correctly referencing trace arrays are affected, as the issue resides in the core ftrace module. The vulnerability applies to every kernel version before the patch that introduces trace_array_options_get(); affected vendor is Linux.
Risk and Exploitability
Scored CVSS 7.8, indicating high severity. The EPSS measurement is less than 1 %, signaling a very low proven exploitation probability. The flaw is not listed in CISA’s KEV catalog. The likely attack vector is local, requiring a user to open an ftrace option file while another user or process removes the corresponding trace array. Though exploitation is unlikely in the wild, the potential for a kernel crash warrants timely patching.
OpenCVE Enrichment