CVE-2026-23309
In the Linux kernel, the following vulnerability has been resolved: tracing: Add NULL pointer check to trigger_data_free() If trigger_data_alloc() fails and returns NULL, event_hist_trigger_parse() jumps to the out_free error path.
Does this matter?
Lower severity and a low EPSS score (0.12%). Track it; it rarely justifies an emergency change on its own.
Description
In the Linux kernel, the following vulnerability has been resolved: tracing: Add NULL pointer check to trigger_data_free() If trigger_data_alloc() fails and returns NULL, event_hist_trigger_parse() jumps to the out_free error path. While kfree() safely handles a NULL pointer, trigger_data_free() does not. This causes a NULL pointer dereference in trigger_data_free() when evaluating data->cmd_ops->set_filter. Fix the problem by adding a NULL pointer check to trigger_data_free(). The problem was found by an experimental code review agent based on gemini-3.1-pro while reviewing backports into v6.18.y.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 0.12% probability · 2th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-476
- Affected
- linux/linux kernel
- Source
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
References
- https://git.kernel.org/stable/c/13dcd9269e225e4c4ceabdaeebe2ce4661b54c6ePatch
- https://git.kernel.org/stable/c/2ce8ece5a78da67834db7728edc801889a64f643Patch
- https://git.kernel.org/stable/c/42b380f97d65e76e7b310facd525f730272daf57Patch
- https://git.kernel.org/stable/c/457965c13f0837a289c9164b842d0860133f6274Patch
- https://git.kernel.org/stable/c/477469223b2b840f436ce204333de87cb17e5d93Patch
- https://git.kernel.org/stable/c/59c15b9cc453b74beb9f04c6c398717e73612dc3Patch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.