CVE-2026-90002

Source
https://cve.org/CVERecord?id=CVE-2026-90002
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90002.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-90002
Downstream
Published
2026-09-16T10:33:12Z
Modified
2026-09-17T03:47:23Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
ftrace: Take trace_array reference before accessing its ftrace_ops
Details

In the Linux kernel, the following vulnerability has been resolved:

ftrace: Take trace_array reference before accessing its ftrace_ops

The trace instance files set_ftrace_filter and set_ftrace_notrace was updated to work with specific trace instances (trace_arrays). The issue is that when these files are opened, there is a small race window where it will use the ftrace_ops from the inode->private pointer to get a reference to the trace_array and then take its reference. The problem is that the ftrace_ops itself could be freed. If the rmdir on the instance happens at the same time the set_ftrace_filter file is opened, the rmdir could have also freed the ftrace_ops and referencing it will cause a use-after-free bug and crash the kernel.

Instead, pass in the trace_array as the file private data (NULL for the top level instance), and then pass both the trace_array and the ftrace_ops to the ftrace_regex_open() function. If the trace_array is NULL, then it just uses the ftrace_ops without the need to take its reference (like normal). If the ftrace_ops is NULL, that is only the case for the top level instance and the global_ops can be used.

This allows the trace_array to have its reference incremented before touching the ftrace_ops that could also be freed when the instance is.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/90xxx/CVE-2026-90002.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
591dffdade9f07692a7dd3ed16830ec24e901ece
Fixed
83fd7eca5ab0d3ac3f23bff889175d847e21af06
Fixed
cee8f286794df916553d8d445eac5c323ec5b0f8
Fixed
9100191e5acb2e5ea2313f436667bb5fce129f47

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90002.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.15.0
Fixed
6.18.52
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90002.json"