Back to overview

CVE-2026-64075

Description
In the Linux kernel, the following vulnerability has been resolved: fprobe: Fix unregister_fprobe() to wait for RCU grace period Commit 4346ba1604093 ("fprobe: Rewrite fprobe on function-graph tracer") changed fprobe to register struct fprobe to an rcu-hlist, but it forgot to wait for RCU GP. Thus there can be use-after-free if the fprobe is released right after unregistering. This can be happened on fprobe event and sample module code. To fix this issue, add synchronize_rcu() in unregister_fprobe(). Note that BPF is OK because fprobe is used as a part of bpf_kprobe_multi_link. This unregisters its fprobe in bpf_kprobe_multi_link_release() and it is deallocated via bpf_kprobe_multi_link_dealloc(), which is invoked from bpf_link_defer_dealloc_rcu_gp() RCU callback. For BPF, this also introduced unregister_fprobe_async() which does NOT wait for RCU grace priod.

Metadata

CVE ID
CVE-2026-64075
State
PUBLISHED
Assigner
Linux
Reserved
2026-07-19 07:54 UTC
Published
2026-07-19 15:39 UTC
Last updated
2026-07-19 15:39 UTC
Vendor / Product
Linux / Linux
Sources
cve.org  ·  NVD

Severity & Metrics

No CVSS data available.

Affected products (2)
VendorProductPlatformVersions
Linux Linux 4346ba1604093305a287e08eb465a9c15ba05b80 < 56b4cfcf1518245493c60fd39c56978f508f1816, 4346ba1604093305a287e08eb465a9c15ba05b80 < a4f6a9005ed6cfd360ef2520430927f05f92ffb0, 4346ba1604093305a287e08eb465a9c15ba05b80 < 657b594b2084b39a4bc6d8493aa2140cb00cea49
Linux Linux 6.14, 0 < 6.14, 6.18.34 ≤ 6.18.*, 7.0.11 ≤ 7.0.* …
Back to overview