CVE-2026-68177
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
10/08/2026
Last modified:
17/08/2026
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
tracing: Delay module ref count for "enable_event" trigger<br />
<br />
Triggers are now delayed from freeing, but can still be triggered until<br />
after the RCU grace period has ended. The freeing of the enable_event data<br />
is put into the private_data_free() callback, but the put of the module<br />
refcount is done immediately.<br />
<br />
It is possible that if a module is removed that has an event that would<br />
enable (or disable) it is still active, it can read the data of the module<br />
after it is removed causing a use-after-free bug.<br />
<br />
Move the trace_event_put_ref() that releases the module into the delayed<br />
callback so that the module can not be removed until any reference to its<br />
events are finished.
Impact
Base Score 3.x
7.80
Severity 3.x
HIGH


