In the Linux kernel, the following vulnerability has been resolved: tracing: Don't dereference...
zetlyn/cve-ghsa vulnerability ghsa GHSA-pm4h-64gj-cjhp cve CVE-2026-97932 known 2026-09-25
https://github.com/advisories/GHSA-pm4h-64gj-cjhp
Properties
| severity | unknownreceipt
What the source handed over{
"credits": [],
"cve_id": "CVE-2026-97932",
"cvss": {
"score": null,
"vector_string": null
},
"cvss_severities": {
"cvss_v3": {
"score": 0.0,
"vector_string": null
},
"cvss_v4": {
"score": 0.0,
"vector_string": null
}
},
"cwes": [],
"description": "In the Linux kernel, the following vulnerability has been resolved:\n\ntracing: Don't dereference trace_event_file in deferred trigger free\n\nThe enable_event trigger defers trace_event_put_ref() to the\ntrigger free kthread, but the trace_event_file can already be freed\nwhen the instance is removed.\n\nKeep the trace_event_call directly in enable_trigger_data so the\ndeferred free does not access the freed trace_event_file.",
"epss": {
"percentage": 0.00189,
"percentile": 0.07669
},
"ghsa_id": "GHSA-pm4h-64gj-cjhp",
"github_reviewed_at": null,
"html_url": "https://github.com/advisories/GHSA-pm4h-64gj-cjhp",
"identifiers": [
{
"type": "GHSA",
"value": "GHSA-pm4h-64gj-cjhp"
},
{
"type": "CVE",
"value": "CVE-2026-97932"
}
],
"nvd_published_at": "2026-09-25T11:17:20Z",
"published_at": "2026-09-25T12:31:29Z",
"references": [
"https://nvd.nist.gov/vuln/detail/CVE-2026-97932",
"https://git.kernel.org/stable/c/67fb91a7f7bb1d958cf9cc249c912bca9b2fc821",
"https://git.kernel.org/stable/c/bcfe2816e6ec46c3f4c58aa4264476665ddb3f69",
"https://github.com/advisories/GHSA-pm4h-64gj-cjhp"
],
"repository_advisory_url": null,
"severity": "unknown",
"source_code_location": "",
"summary": "In the Linux kernel, the following vulnerability has been resolved:\n\ntracing: Don't dereference...",
"type": "unreviewed",
"updated_at": "2026-09-25T12:31:37Z",
"url": "https://api.github.com/advisories/GHSA-pm4h-64gj-cjhp",
"vulnerabilities": [],
"withdrawn_at": null
} |
|---|
Text
In the Linux kernel, the following vulnerability has been resolved:
tracing: Don't dereference...
In the Linux kernel, the following vulnerability has been resolved:
tracing: Don't dereference trace_event_file in deferred trigger free
The enable_event trigger defers trace_event_put_ref() to the
trigger free kthread, but the trace_event_file can already be freed
when the instance is removed.
Keep the trace_event_call directly in enable_trigger_data so the
deferred free does not access the freed trace_event_file.