Description
In the Linux kernel, the following vulnerability has been resolved:

samples/ftrace: Fix kthread_stop() on ERR_PTR in ftrace-direct-multi-modify

ftrace_direct_multi_init() assigns kthread_run()'s return value to
simple_tsk without an IS_ERR() check. When kthread_run() fails it
returns ERR_PTR(-ENOMEM), but init still returns 0, so the module loads
with simple_tsk holding an error pointer. On unload,
ftrace_direct_multi_exit() then passes that ERR_PTR to kthread_stop(),
leading to a null-pointer-dereference.

Check the return value of kthread_run() with IS_ERR(); on failure,
unregister the ftrace direct call and propagate the error code.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Kernel Crash/Denial of Service
Action: Patch
AI Analysis

Impact

A failure in the Linux kernel ftrace direct multi module can cause a kernel crash when the module is unloaded. In the initialization function, the result of kthread_run() is assigned to a task pointer without verifying if the function returned an error pointer. If the thread creation fails, the function returns ERR_PTR(-ENOMEM), but the module reports success and continues to load. When the module is later unloaded, the exit function passes this erroneous pointer to kthread_stop(), causing a null‑pointer dereference in the kernel. This results in a crash that can bring the affected system down, effectively denying service for the machine or host.

Affected Systems

The affected product is the Linux kernel, specifically those releases that include the ftrace_direct_multi module, which is part of the mainline samples. No specific version numbers are supplied, but any kernel that has not incorporated the described fix is vulnerable. The issue applies to all vendor distributions that ship the unpatched kernel.

Risk and Exploitability

The EPSS score is below 1 %, indicating a very low probability of exploitation derived from current threat data. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires local, privileged access to load or unload kernel modules, typically available only to root or users with CAP_SYS_MODULE. As a result, the attack vector would be local, and the risk is mitigated by limiting privileged access. Nonetheless, the crash severity (kernel fault) makes it a high‑impact local vulnerability if an attacker can execute the exploit path.

Generated by OpenCVE AI on September 20, 2026 at 04:31 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a kernel version that includes the fix—upgrade to a release that incorporates the commits referenced in the advisory (for example, the changes committed to the kernel tree under the provided URLs).
  • If an immediate kernel upgrade is not possible, prevent the ftrace_direct_multi module from loading by adding a blacklist entry (e.g., echo "blacklist ftrace_direct_multi" > /etc/modprobe.d/blacklist-ftrace_multi.conf).
  • If the module must remain loaded for operational reasons, avoid unloading it; a system reboot will remove the module, preventing the crash during the unload process.

Generated by OpenCVE AI on September 20, 2026 at 04:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sun, 20 Sep 2026 05:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: samples/ftrace: Fix kthread_stop() on ERR_PTR in ftrace-direct-multi-modify ftrace_direct_multi_init() assigns kthread_run()'s return value to simple_tsk without an IS_ERR() check. When kthread_run() fails it returns ERR_PTR(-ENOMEM), but init still returns 0, so the module loads with simple_tsk holding an error pointer. On unload, ftrace_direct_multi_exit() then passes that ERR_PTR to kthread_stop(), leading to a null-pointer-dereference. Check the return value of kthread_run() with IS_ERR(); on failure, unregister the ftrace direct call and propagate the error code.
Title samples/ftrace: Fix kthread_stop() on ERR_PTR in ftrace-direct-multi-modify
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:05:48.921Z

Reserved: 2026-09-11T19:38:34.784Z

Link: CVE-2026-90066

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:16:55.437

Modified: 2026-09-17T17:16:55.437

Link: CVE-2026-90066

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T04:45:16Z

Weaknesses