CVE-2026-64028: tracing: Avoid NULL return from hist_field_name() on truncation
Greg Kroah-Hartman <[email protected]>
| Newsgroups | org.kernel.vger.linux-cve-announce |
|---|---|
| Message-ID | <2026071903-CVE-2026-64028-1c01@gregkh> |
From: Greg Kroah-Hartman <[email protected]> Description =========== In the Linux kernel, the following vulnerability has been resolved: tracing: Avoid NULL return from hist_field_name() on truncation hist_field_name() returns "" everywhere except the fully-qualified VAR_REF/EXPR case, where snprintf() truncation returns NULL early and bypasses the bottom NULL->"" guard. Callers don't expect NULL: strcat(expr, hist_field_name(field, 0)) at trace_events_hist.c:1758 and the strcmp() in the sort-key match loop at :4804 both deref it. system and event_name are bounded by MAX_EVENT_NAME_LEN, but the field name on a VAR_REF is kstrdup'd from a histogram variable name parsed out of the trigger string and has no length cap, so a long enough var name in a fully qualified reference can reach the truncation path. Keep the length check but leave field_name as "" on overflow. The Linux kernel CVE team has assigned CVE-2026-64028 to this issue. Affected and fixed versions =========================== Issue introduced in 6.6.141 with commit 9399a92989354e34086f9a5c379493217df83c5e and fixed in 6.6.142 with commit e91687643c440ca3997d67646e6f80b92edc6703 Issue introduced in 6.12.91 with commit 3cb6cb9c5a547a1979ad74f38eefe8e3687d96e0 and fixed in 6.12.92 with commit be4e99038c1603fa6b329d8ee3e364825e17c353 Issue introduced in 6.18.33 with commit 0402c60abe769098d77f3b3bd1e29a97922b614b and fixed in 6.18.34 with commit d6c8b3ebdcdb12b59ad4212acb137cc56cae453d Issue introduced in 7.0.10 with commit 6929e650db8451a9975ac0a631ba2d6e5d1e80ba and fixed in 7.0.11 with commit 915c1254fe0788abddc31095b360e9dc98907a34 Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-64028 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: kernel/trace/trace_events_hist.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/e3f5d42cdc2f167719564693675f1eead81378ea https://git.kernel.org/stable/c/37377b39ff86dacbc533275c1155210d4fd5dc91 https://git.kernel.org/stable/c/0402a1d3ddec565132867337ed44514a09d84728 https://git.kernel.org/stable/c/e91687643c440ca3997d67646e6f80b92edc6703 https://git.kernel.org/stable/c/be4e99038c1603fa6b329d8ee3e364825e17c353 https://git.kernel.org/stable/c/d6c8b3ebdcdb12b59ad4212acb137cc56cae453d https://git.kernel.org/stable/c/915c1254fe0788abddc31095b360e9dc98907a34 https://git.kernel.org/stable/c/576ec047d20b368b43c4d5db98c4f2e0f3c101ec