CVE-2026-89750

Source
https://cve.org/CVERecord?id=CVE-2026-89750
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89750.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-89750
Downstream
Published
2026-09-11T19:46:54Z
Modified
2026-09-14T03:46:36Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
tracing/user_events: Clear copied tracing state before fork duplication
Details

In the Linux kernel, the following vulnerability has been resolved:

tracing/user_events: Clear copied tracing state before fork duplication

dup_task_struct() copies user_event_mm from the parent into the child, without grabbing a reference to it. user_event_mm_dup() should replace it, but it leaves that copied pointer unmodified if user_event_mm_alloc() fails.

When the child exits, user_event_mm_remove() decrements a reference the child never owned, which ultimately frees user_event_mm, while the parent still as a stale pointer to it. This creates a UAF, which KASAN reports as:

BUG: KASAN: slab-use-after-free in
current_user_event_mm+0x51/0x1d0 Write of size 4 at addr
ffff888005010d30 by task init/44

Call Trace:
 <TASK>
 kasan_report+0xce/0x100
 kasan_check_range+0x10f/0x1e0
 current_user_event_mm+0x51/0x1d0
 user_events_ioctl+0x82e/0x15c0
 __x64_sys_ioctl+0x139/0x1c0
 do_syscall_64+0xce/0x450
 entry_SYSCALL_64_after_hwframe+0x77/0x7f

Allocated by task 44:
 __kasan_kmalloc+0x8f/0xa0
 __kmalloc_cache_noprof+0x180/0x3a0
 user_event_mm_alloc+0x3c/0x1f0
 current_user_event_mm+0x88/0x1d0

Freed by task 42:
 __kasan_slab_free+0x43/0x70
 kfree+0x13a/0x390
 process_one_work+0x696/0xf90
 worker_thread+0x420/0xba0

The fix simply clears the copied pointer before any possible failure. In case of failure, the child then has nothing to free.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89750.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
7235759084a4f8524a46bd2638885ff3b34ce279
Fixed
63b39e49a4c9d68e010e96b26fc7374f0864f2b1
Fixed
25a0758cf6bdbfddac2be71124c9bd0692f4b0b1
Fixed
b799f67119aff179719a0b1e12441ebbdaaf62f9
Fixed
390f6bd8583d177029d9df4bea6667509e55a765

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89750.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.4.0
Fixed
6.12.109
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.50
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89750.json"