Impact
In the Linux kernel, the files show_event_filters and show_event_triggers expose trace array content but fail to increment a reference to the trace_array while opened. If the trace_array is removed (e.g., via rmdir) while a task reads these files, the array can be freed and a subsequent memory access results in a use‑after‑free crash. This loss of control can lead to a denial‑of‑service by crashing the kernel, potentially affecting all user space processes.
Affected Systems
The vulnerability affects the Linux kernel, specifically any version that lacks the trace_array reference modification in the show_event_filters and show_event_triggers files. No specific kernel version number is listed; the issue was addressed in a recent patch set in the mainline repository. Systems running unpatched kernels are susceptible.
Risk and Exploitability
The CVSS score of 7.8 reflects a moderate to high severity, with the EPSS score < 1% indicating a low probability of exploitation as of the latest data set. The vulnerability is not listed in CISA's KEV catalog. It is likely exploitable only from a local user context or by an attacker with the ability to trigger removal of the trace array while a read is in progress. The fix requires kernel recompilation or binary upgrade; otherwise a kernel crash can be triggered, leading to denial of service.
OpenCVE Enrichment