CVE-2026-23309
Published: Mar 25, 2026
Modified: May 11, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: tracing: Add NULL pointer check to trigger_data_free() If trigger_data_alloc() fails and returns NULL, event_hist_trigger_parse() jumps to the out_free error path. While kfree() safely handles a NULL pointer, trigger_data_free() does not. This causes a NULL pointer dereference in trigger_data_free() when evaluating data->cmd_ops->set_filter. Fix the problem by adding a NULL pointer check to trigger_data_free(). The problem was found by an experimental code review agent based on gemini-3.1-pro while reviewing backports into v6.18.y.
| Vendor | Product | Versions |
|---|---|---|
Linux | Linux | affected c10f0efe57728508d796ae4ba7abe4c14ec3d8ef - < 13dcd9269e225e4c4ceabdaeebe2ce4661b54c6eaffected 7e6556e9329bc484e9dcdab6e346d959267c0636 - < 59c15b9cc453b74beb9f04c6c398717e73612dc3affected 9b0513905e0598b9f8cfccab8e47497aed5d935d - < 42b380f97d65e76e7b310facd525f730272daf57affected 335dfe4bc6368e70e8c15419375cf609c4f85558 - < 2ce8ece5a78da67834db7728edc801889a64f643affected e42efbe9754da78eafe11f6bd3ca9c8a094a752a - < 477469223b2b840f436ce204333de87cb17e5d93+1 more versions |
Linux | Linux | affected 6.1.165 - < 6.1.167affected 6.6.128 - < 6.6.130affected 6.12.75 - < 6.12.77affected 6.18.14 - < 6.18.17affected 6.19.4 - < 6.19.7 |
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now