{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  tracing: Fix use-after-free with same-name named triggers  When two hist triggers on different events are registered with the same name=, the second one reuses the first as named_data.  Both are added to tr-\u003ehist_vars by save_hist_vars() during event_hist_trigger_parse(), because save_hist_vars() is called before event_trigger_register() while the named reuse is only detected later, in hist_register_trigger().  In the named-data branch hist_register_trigger() then frees the second histogram's hist_data via destroy_hist_data(), but never removes its tr-\u003ehist_vars list entry, leaving a dangling pointer and leaking the trace_array reference it holds.  A later hist trigger that references a variable makes find_var_file() walk tr-\u003ehist_vars and dereference the freed hist_data.  The bug is reproducible from userspace by writing three hist triggers to tracefs:    cd /sys/kernel/tracing   echo 'hist:keys=common_pid:x=common_pid:name=mh' \u003e events/sched/sched_switch/trigger   echo 'hist:keys=common_pid:x=common_pid:name=mh' \u003e events/sched/sched_process_fork/trigger   echo 'hist:keys=common_pid:vals=$x' \u003e events/sched/sched_process_exit/trigger  The third write panics the kernel:    BUG: KASAN: slab-use-after-free in find_var_file.part.0+0x272/0x290   Read of size 8 at addr ffff888001f8a0e0 by task sh/1   CPU: 1 UID: 0 PID: 1 Comm: sh Tainted: G      D          N   Call Trace:     find_var_file.part.0     find_event_var     parse_atom     parse_expr     __create_val_field     event_hist_trigger_parse     trigger_process_regex     event_trigger_write     vfs_write     ksys_write     do_syscall_64     entry_SYSCALL_64_after_hwframe   Allocated by task 1:     event_hist_trigger_parse   Freed by task 1:     hist_register_trigger+0x618/0xa30     event_hist_trigger_parse   The buggy address belongs to freed 2048-byte region   Oops: general protection fault ... RIP: find_var_file.part.0   Kernel panic - not syncing: Attempted to kill init! exitcode=0x0000000b  Fix by removing the hist_data from tr-\u003ehist_vars and releasing the trace_array reference in the named-data branch of hist_register_trigger() before freeing the hist_data.",
  "id": "DEBIAN-CVE-2026-89746",
  "modified": "2026-09-15T08:47:44.572433629Z",
  "published": "2026-09-11T20:20:05.373Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-89746"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ],
  "upstream": [
    "CVE-2026-89746"
  ]
}