CVE-2026-68177

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
10/08/2026
Last modified:
17/08/2026

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> tracing: Delay module ref count for "enable_event" trigger<br /> <br /> Triggers are now delayed from freeing, but can still be triggered until<br /> after the RCU grace period has ended. The freeing of the enable_event data<br /> is put into the private_data_free() callback, but the put of the module<br /> refcount is done immediately.<br /> <br /> It is possible that if a module is removed that has an event that would<br /> enable (or disable) it is still active, it can read the data of the module<br /> after it is removed causing a use-after-free bug.<br /> <br /> Move the trace_event_put_ref() that releases the module into the delayed<br /> callback so that the module can not be removed until any reference to its<br /> events are finished.