CVE-2026-64028: tracing: Avoid NULL return from hist_field_name() on truncation

Greg Kroah-Hartman <[email protected]>
Newsgroups org.kernel.vger.linux-cve-announce
Message-ID <2026071903-CVE-2026-64028-1c01@gregkh>
From: Greg Kroah-Hartman <[email protected]>

Description
===========

In the Linux kernel, the following vulnerability has been resolved:

tracing: Avoid NULL return from hist_field_name() on truncation

hist_field_name() returns "" everywhere except the fully-qualified
VAR_REF/EXPR case, where snprintf() truncation returns NULL early
and bypasses the bottom NULL->"" guard. Callers don't expect NULL:
strcat(expr, hist_field_name(field, 0)) at trace_events_hist.c:1758
and the strcmp() in the sort-key match loop at :4804 both deref it.

system and event_name are bounded by MAX_EVENT_NAME_LEN, but the
field name on a VAR_REF is kstrdup'd from a histogram variable
name parsed out of the trigger string and has no length cap, so
a long enough var name in a fully qualified reference can reach
the truncation path.

Keep the length check but leave field_name as "" on overflow.

The Linux kernel CVE team has assigned CVE-2026-64028 to this issue.


Affected and fixed versions
===========================

	Issue introduced in 6.6.141 with commit 9399a92989354e34086f9a5c379493217df83c5e and fixed in 6.6.142 with commit e91687643c440ca3997d67646e6f80b92edc6703
	Issue introduced in 6.12.91 with commit 3cb6cb9c5a547a1979ad74f38eefe8e3687d96e0 and fixed in 6.12.92 with commit be4e99038c1603fa6b329d8ee3e364825e17c353
	Issue introduced in 6.18.33 with commit 0402c60abe769098d77f3b3bd1e29a97922b614b and fixed in 6.18.34 with commit d6c8b3ebdcdb12b59ad4212acb137cc56cae453d
	Issue introduced in 7.0.10 with commit 6929e650db8451a9975ac0a631ba2d6e5d1e80ba and fixed in 7.0.11 with commit 915c1254fe0788abddc31095b360e9dc98907a34

Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.

Unaffected versions might change over time as fixes are backported to
older supported kernel versions.  The official CVE entry at
	https://cve.org/CVERecord/?id=CVE-2026-64028
will be updated if fixes are backported, please check that for the most
up to date information about this issue.


Affected files
==============

The file(s) affected by this issue are:
	kernel/trace/trace_events_hist.c


Mitigation
==========

The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes.  Individual
changes are never tested alone, but rather are part of a larger kernel
release.  Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all.  If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
	https://git.kernel.org/stable/c/e3f5d42cdc2f167719564693675f1eead81378ea
	https://git.kernel.org/stable/c/37377b39ff86dacbc533275c1155210d4fd5dc91
	https://git.kernel.org/stable/c/0402a1d3ddec565132867337ed44514a09d84728
	https://git.kernel.org/stable/c/e91687643c440ca3997d67646e6f80b92edc6703
	https://git.kernel.org/stable/c/be4e99038c1603fa6b329d8ee3e364825e17c353
	https://git.kernel.org/stable/c/d6c8b3ebdcdb12b59ad4212acb137cc56cae453d
	https://git.kernel.org/stable/c/915c1254fe0788abddc31095b360e9dc98907a34
	https://git.kernel.org/stable/c/576ec047d20b368b43c4d5db98c4f2e0f3c101ec
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.