{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-90013","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.781Z","datePublished":"2026-09-16T10:33:20.136Z","dateUpdated":"2026-10-03T10:56:58.061Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-10-03T10:56:58.061Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ntracing: Take trace_array reference when opening options file\n\nThe options files do not take the trace_array reference for the options\nthey represent. This could cause a use-after-free kernel crash if one of\nthese files is opened by one task and another task removes the instance\nthat the option is for. Because it doesn't take a reference upon opening,\nit will not stop the removal which will free the options descriptor that\nis being used.\n\nAs the options are somewhat dynamic in their creation at boot up, each\nfile represents a flag in the trace_array. The trace_array has an array of\nindexes to represent each of these flags that is stored in the\ntrace_flags_index array. The address of the index array element is used to\npass to the inode->i_private pointer. Then that element is read which\nholds the index (which represents the flag) and then the index is used to\ncalculate the trace_array descriptor from its trace_flags_index array.\n\nOne issue is that the index element can not be referenced until the\ntrace_array's reference is taken. To handle this, create a new helper\nfunction called: trace_array_options_get() that will iterate all the\nexisting trace_arrays in the ftrace_trace_arrays list (under the\ntrace_types_lock), and compare the passed in address of the index element\nwith the entire array of the trace_array's trace_flags_index array.\nIf it matches, then up the corresponding trace_array's reference and\nreturn."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The UAF is reached only via local tracefs: open() of an instance options file (tracing_open_generic -> trace_options_core_read/write) then rmdir of that instance (__remove_instance). No network, adjacent-radio, or physical-device path reaches get_tr_index() or the freed trace_array.\nAC:L - The attacker fully controls both sides: open an instance options file (no trace_array ref), rmdir the instance so __remove_instance kfree()s the trace_array, then read/write the still-open fd. That sequence is deterministic and retryable; CONFIG_TRACING with instances is standard, not a rare config.\nPR:L - tracing_open_generic() and instance mkdir/rmdir enforce only LOCKDOWN_TRACEFS and DAC (options 0640, dirs 0750) with no capable() gate. Android/Perfetto, ChromeOS, and gid=/uid= tracing mounts routinely delegate this to unprivileged tracing accounts, matching CVE-2026-74606 and CVE-2026-89747.\nUI:N - The attacker mkdir()s their own tracing instance, opens options, rmdir()s the instance, and reads or writes the fd themselves. No victim mount, click, or cooperating process is required.\nS:U - The use-after-free corrupts a kernel trace_array in the tracing subsystem on the same host. It can yield local privilege escalation but does not cross a VM, IOMMU, or other security authority.\nC:H - After rmdir, get_tr_index() reads the freed trace_flags_index byte and reconstructs a trace_array, then trace_options_core_read() loads tr->trace_flags. Reclaiming that slab lets the attacker control the object and obtain an arbitrary kernel read, which kernel CNA guidance scores High for UAF.\nI:H - trace_options_core_write() calls set_tracer_flag() on the freed/reused trace_array, including tr->current_trace->flag_changed and writes to tr->trace_flags and related tracing state. Heap spraying that object yields an arbitrary kernel write and control-flow hijack primitive.\nA:H - Dereferencing the kfree()d trace_array in get_tr_index()/trace_options_core_read() oopses or panics the kernel, which the fix describes as a use-after-free kernel crash. The attacker can retrigger that crash at will."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["kernel/trace/trace.c"],"versions":[{"version":"577b785f55168d5acb3d123ba41bfe8d7981e044","lessThan":"97ceaffbd672449ad7ead5ae8788dce16374b0c1","status":"affected","versionType":"git"},{"version":"577b785f55168d5acb3d123ba41bfe8d7981e044","lessThan":"d0f37d77b9b4b241e0b30ef2562f6353cbda3bec","status":"affected","versionType":"git"},{"version":"577b785f55168d5acb3d123ba41bfe8d7981e044","lessThan":"64a41f4a9a968f54f3792399aa4d2a9fdb23b0a5","status":"affected","versionType":"git"},{"version":"577b785f55168d5acb3d123ba41bfe8d7981e044","lessThan":"f2951ebd15c36a1ea4820a7f0cbb0b5f1c028b73","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["kernel/trace/trace.c"],"versions":[{"version":"2.6.30","status":"affected"},{"version":"0","lessThan":"2.6.30","status":"unaffected","versionType":"semver"},{"version":"6.12.112","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.52","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.5","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.30","versionEndExcluding":"6.12.112"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.30","versionEndExcluding":"6.18.52"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.30","versionEndExcluding":"7.2.5"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.30","versionEndExcluding":"7.3-rc2"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/97ceaffbd672449ad7ead5ae8788dce16374b0c1"},{"url":"https://git.kernel.org/stable/c/d0f37d77b9b4b241e0b30ef2562f6353cbda3bec"},{"url":"https://git.kernel.org/stable/c/64a41f4a9a968f54f3792399aa4d2a9fdb23b0a5"},{"url":"https://git.kernel.org/stable/c/f2951ebd15c36a1ea4820a7f0cbb0b5f1c028b73"}],"title":"tracing: Take trace_array reference when opening options file","x_generator":{"engine":"bippy-1.2.0"}}}}