Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-68177

Gravedad CVSS v3.1:
ALTA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
10/08/2026
Última modificación:
17/08/2026

Descripción

*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> tracing: Delay module ref count for "enable_event" trigger<br /> <br /> Triggers are now delayed from freeing, but can still be triggered until<br /> after the RCU grace period has ended. The freeing of the enable_event data<br /> is put into the private_data_free() callback, but the put of the module<br /> refcount is done immediately.<br /> <br /> It is possible that if a module is removed that has an event that would<br /> enable (or disable) it is still active, it can read the data of the module<br /> after it is removed causing a use-after-free bug.<br /> <br /> Move the trace_event_put_ref() that releases the module into the delayed<br /> callback so that the module can not be removed until any reference to its<br /> events are finished.