AZL-100259

See a problem?
Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-100259.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-100259
Upstream
Published
2026-09-11T20:20:05Z
Modified
2026-09-13T06:06:36Z
Summary
CVE-2026-89750 affecting package kernel 6.6.150.1-1
Details

In the Linux kernel, the following vulnerability has been resolved:

tracing/user_events: Clear copied tracing state before fork duplication

dup_task_struct() copies user_event_mm from the parent into the child, without grabbing a reference to it. user_event_mm_dup() should replace it, but it leaves that copied pointer unmodified if user_event_mm_alloc() fails.

When the child exits, user_event_mm_remove() decrements a reference the child never owned, which ultimately frees user_event_mm, while the parent still as a stale pointer to it. This creates a UAF, which KASAN reports as:

BUG: KASAN: slab-use-after-free in
current_user_event_mm+0x51/0x1d0 Write of size 4 at addr
ffff888005010d30 by task init/44

Call Trace:
 <TASK>
 kasan_report+0xce/0x100
 kasan_check_range+0x10f/0x1e0
 current_user_event_mm+0x51/0x1d0
 user_events_ioctl+0x82e/0x15c0
 __x64_sys_ioctl+0x139/0x1c0
 do_syscall_64+0xce/0x450
 entry_SYSCALL_64_after_hwframe+0x77/0x7f

Allocated by task 44:
 __kasan_kmalloc+0x8f/0xa0
 __kmalloc_cache_noprof+0x180/0x3a0
 user_event_mm_alloc+0x3c/0x1f0
 current_user_event_mm+0x88/0x1d0

Freed by task 42:
 __kasan_slab_free+0x43/0x70
 kfree+0x13a/0x390
 process_one_work+0x696/0xf90
 worker_thread+0x420/0xba0

The fix simply clears the copied pointer before any possible failure. In case of failure, the child then has nothing to free.

References

Affected packages

Azure Linux:3 / kernel

Package

Name
kernel
Purl
pkg:rpm/azure-linux/kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
6.6.150.1-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-100259.json"