CVE-2026-97920: tracing: Keep the entry count when the histogram stats allocation fails

Published Sep 25, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

tracing: Keep the entry count when the histogram stats allocation fails

printentries() uses nentries both as the number of sort entries and as its own return value, so the -ENOMEM it stores when the stats allocation fails overwrites the count that the cleanup still needs:

nentries = tracingmapsortentries(map, ...); if (nentries < 0) return nentries; ... if (!stats) { nentries = -ENOMEM; goto out; } ... out: tracingmapdestroysortentries(sortentries, nentries);

tracingmapdestroysortentries() takes an unsigned int and loops up to it, so -ENOMEM arrives as 4294967284. It walks an array of at most map->maxelts pointers and calls destroysortentry(), which dereferences and frees, on whatever lies past the end.

Reading the hist file of a trigger with a .percent value, with that allocation forced to fail:

BUG: KASAN: vmalloc-out-of-bounds in tracingmapdestroysortentries+0xa0/0xb0 Read of size 8 at addr ffffc90000045000 by task init/1 tracingmapdestroysortentries+0xa0/0xb0 histshow+0x6f7/0x1df0 seqreaditer+0x2b8/0x1190 vfsread+0x176/0xa40 The buggy address belongs to a 4-page vmalloc region starting at ffffc90000041000 allocated at tracingmapsortentries+0x5c/0xd50

A few pages further the fault is fatal. The registers at the oops confirm the bound: the loop's end pointer less the array start, over the pointer size, is 4294967284.

Return the error in a separate variable and leave nentries holding the count, the way tracingmapsortentries() does on its own error path.

The stats block is only entered for a value carrying .percent or .graph, which createvalfield() has rejected since v6.3, so this cannot be reached in mainline as it stands. It becomes reachable again with "tracing: hist: let values keep the percent and graph modifiers", so it should be applied first.

Affected Software

1 affected component
Linux Linux kernel

Event History

Sep 25, 2026
CVE Published
via MITRE·10:22 AM
Data Sourced
via MITRE·10:22 AM
Description
Data Sourced
via NVD·11:17 AM
Description

Frequently Asked Questions

1

What conditions are required to trigger the out-of-bounds cleanup?

The affected path is reached when the hist file for a tracing trigger using a .percent value is read and the histogram statistics allocation fails. The failure causes -ENOMEM to be used as the cleanup entry count.

2

How can I recognize a likely occurrence of this issue?

With KASAN enabled, the reported failure is a vmalloc-out-of-bounds read in tracing_map_destroy_sort_entries(), reached through hist_show(), seq_read_iter(), and vfs_read(). The cleanup may iterate far beyond the allocated sort-entry array because the negative error is interpreted as an unsigned count.

3

What remediation is available?

The issue is resolved by the fixes referenced in the listed Linux stable commits: 9bd8321f5370295d1ae96dd17d43be3c9edd441b, c80b2a8067d58ff7d268ceef781c68b37a16c321, and 17e87ce55f877efff1b08fe509e8bf91378cbbc9.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203