Description
In the Linux kernel, the following vulnerability has been resolved:

bpf: Mark tracing_multi trampolines as ftrace managed

Since tracing_multi link does not set ftrace_managed, it would fail to
release the tracing_multi link when attaching tracing_multi link and
then attaching fentry link.

[ 3.714215] WARNING: kernel/bpf/trampoline.c:1727 at bpf_trampoline_multi_detach+0x20b/0x240, CPU#1: test_progs/97
...
[ 3.733170] bpf_tracing_multi_link_release+0x14/0x30
[ 3.733890] bpf_link_free+0x58/0x130
[ 3.734414] bpf_link_release+0x23/0x30

Fix it by setting 'ftrace_managed = true' in register_fentry_multi().
Published: 2026-09-17
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Resource Leak
Action: Apply Patch
AI Analysis

Impact

A bug in the Linux kernel's BPF tracing module causes the tracing_multi link to not be marked as ftrace managed. When a tracing_multi link is attached followed by an fentry link, the kernel fails to release the original link, leading to a resource leak that can exhaust kernel BPF link resources if repeated. This flaw corresponds to a resource management weakness (CWE‑401).

Affected Systems

All Linux distributions that ship a kernel containing the unpatched BPF tracing_multi implementation are affected. The bug exists in the core Linux kernel and applies to every system that can load BPF programs and has the capability to attach tracing links, regardless of distribution or specific kernel configuration.

Risk and Exploitability

The CVSS score of 7.8 indicates a high severity of the flaw. The EPSS score of less than 1 % signifies a low likelihood of exploitation at the time of this analysis, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is local and requires the ability to load BPF programs, such as a user with CAP_SYS_ADMIN privileges. An attacker could repetitively attach tracing_multi and fentry links, potentially exhausting BPF link resources and destabilizing the kernel. However, the CVE description does not explicitly state that this leads to a denial of service, so the impact is inferred but not definitively proven.

Generated by OpenCVE AI on September 20, 2026 at 01:37 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that includes the patch setting ftrace_managed to true in register_fentry_multi().
  • If an upgrade is not feasible, limit the use of tracing_multi links or switch to BPF interfaces that correctly set ftrace_managed until a patched kernel is available.
  • Monitor kernel logs for the bpf_trampoline_multi_detach warning to detect unresolved link leaks early.

Generated by OpenCVE AI on September 20, 2026 at 01:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 02:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-399
CWE-401

Sat, 19 Sep 2026 17:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-368

Sat, 19 Sep 2026 10:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-368

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: bpf: Mark tracing_multi trampolines as ftrace managed Since tracing_multi link does not set ftrace_managed, it would fail to release the tracing_multi link when attaching tracing_multi link and then attaching fentry link. [ 3.714215] WARNING: kernel/bpf/trampoline.c:1727 at bpf_trampoline_multi_detach+0x20b/0x240, CPU#1: test_progs/97 ... [ 3.733170] bpf_tracing_multi_link_release+0x14/0x30 [ 3.733890] bpf_link_free+0x58/0x130 [ 3.734414] bpf_link_release+0x23/0x30 Fix it by setting 'ftrace_managed = true' in register_fentry_multi().
Title bpf: Mark tracing_multi trampolines as ftrace managed
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:55:58.964Z

Reserved: 2026-09-17T16:02:15.086Z

Link: CVE-2026-93111

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:18:05.580

Modified: 2026-09-18T18:18:20.993

Link: CVE-2026-93111

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T01:45:17Z

Weaknesses