CVE-2026-90002 is a vulnerability in Linux Kernel
Published on September 16, 2026
ftrace: Take trace_array reference before accessing its ftrace_ops
In the Linux kernel, the following vulnerability has been resolved:
ftrace: Take trace_array reference before accessing its ftrace_ops
The trace instance files set_ftrace_filter and set_ftrace_notrace was
updated to work with specific trace instances (trace_arrays). The issue is
that when these files are opened, there is a small race window where it
will use the ftrace_ops from the inode->private pointer to get a reference
to the trace_array and then take its reference. The problem is that the
ftrace_ops itself could be freed. If the rmdir on the instance happens at
the same time the set_ftrace_filter file is opened, the rmdir could have
also freed the ftrace_ops and referencing it will cause a use-after-free
bug and crash the kernel.
Instead, pass in the trace_array as the file private data (NULL for the
top level instance), and then pass both the trace_array and the ftrace_ops
to the ftrace_regex_open() function. If the trace_array is NULL, then it
just uses the ftrace_ops without the need to take its reference (like
normal). If the ftrace_ops is NULL, that is only the case for the top
level instance and the global_ops can be used.
This allows the trace_array to have its reference incremented before
touching the ftrace_ops that could also be freed when the instance is.
Products Associated with CVE-2026-90002
Want to know whenever a new CVE is published for Linux Kernel? stack.watch will email you.
Affected Versions
Linux:- Version 591dffdade9f07692a7dd3ed16830ec24e901ece and below 83fd7eca5ab0d3ac3f23bff889175d847e21af06 is affected.
- Version 591dffdade9f07692a7dd3ed16830ec24e901ece and below cee8f286794df916553d8d445eac5c323ec5b0f8 is affected.
- Version 591dffdade9f07692a7dd3ed16830ec24e901ece and below 9100191e5acb2e5ea2313f436667bb5fce129f47 is affected.
- Version 3.15 is affected.
- Before 3.15 is unaffected.
- Version 6.18.52, <= 6.18.* is unaffected.
- Version 7.2.5, <= 7.2.* is unaffected.
- Version 7.3-rc2, <= * is unaffected.