CVE-2026-89750 is a vulnerability in Linux Kernel
Published on September 11, 2026
tracing/user_events: Clear copied tracing state before fork duplication
In the Linux kernel, the following vulnerability has been resolved:
tracing/user_events: Clear copied tracing state before fork duplication
dup_task_struct() copies user_event_mm from the parent into the child,
without grabbing a reference to it. user_event_mm_dup() should
replace it, but it leaves that copied pointer unmodified if
user_event_mm_alloc() fails.
When the child exits, user_event_mm_remove() decrements a reference
the child never owned, which ultimately frees user_event_mm, while
the parent still as a stale pointer to it. This creates a UAF, which
KASAN reports as:
BUG: KASAN: slab-use-after-free in
current_user_event_mm+0x51/0x1d0 Write of size 4 at addr
ffff888005010d30 by task init/44
Call Trace:
<TASK>
kasan_report+0xce/0x100
kasan_check_range+0x10f/0x1e0
current_user_event_mm+0x51/0x1d0
user_events_ioctl+0x82e/0x15c0
__x64_sys_ioctl+0x139/0x1c0
do_syscall_64+0xce/0x450
entry_SYSCALL_64_after_hwframe+0x77/0x7f
Allocated by task 44:
__kasan_kmalloc+0x8f/0xa0
__kmalloc_cache_noprof+0x180/0x3a0
user_event_mm_alloc+0x3c/0x1f0
current_user_event_mm+0x88/0x1d0
Freed by task 42:
__kasan_slab_free+0x43/0x70
kfree+0x13a/0x390
process_one_work+0x696/0xf90
worker_thread+0x420/0xba0
The fix simply clears the copied pointer before any possible failure.
In case of failure, the child then has nothing to free.
Products Associated with CVE-2026-89750
Want to know whenever a new CVE is published for Linux Kernel? stack.watch will email you.
Affected Versions
Linux:- Version 7235759084a4f8524a46bd2638885ff3b34ce279 and below 63b39e49a4c9d68e010e96b26fc7374f0864f2b1 is affected.
- Version 7235759084a4f8524a46bd2638885ff3b34ce279 and below 25a0758cf6bdbfddac2be71124c9bd0692f4b0b1 is affected.
- Version 7235759084a4f8524a46bd2638885ff3b34ce279 and below b799f67119aff179719a0b1e12441ebbdaaf62f9 is affected.
- Version 7235759084a4f8524a46bd2638885ff3b34ce279 and below 390f6bd8583d177029d9df4bea6667509e55a765 is affected.
- Version 6.4 is affected.
- Before 6.4 is unaffected.
- Version 6.12.109, <= 6.12.* is unaffected.
- Version 6.18.50, <= 6.18.* is unaffected.
- Version 7.2.4, <= 7.2.* is unaffected.
- Version 7.3-rc1, <= * is unaffected.