CVE-2026-72012
In the Linux kernel, the following vulnerability has been resolved: tracing/osnoise: Call synchronize_rcu() when unregistering This ensures that any RCU readers traversing the instance list have finished, before releasing the reference on the tracer…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.16%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
In the Linux kernel, the following vulnerability has been resolved: tracing/osnoise: Call synchronize_rcu() when unregistering This ensures that any RCU readers traversing the instance list have finished, before releasing the reference on the tracer that the instance points to.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.16% probability · 6th percentile
- CISA KEV
- Not listed
- Source
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
References
- https://git.kernel.org/stable/c/38366140dc8ee3568c7f0191d517e117963bd580
- https://git.kernel.org/stable/c/3c693635bb7b3a9b6645831a84fed2af46cdf249
- https://git.kernel.org/stable/c/428cedade9b2cc8e48f00742df0cfd770e77a803
- https://git.kernel.org/stable/c/dd0160a0842337f12e7694d68b184050afc6d3a4
- https://git.kernel.org/stable/c/fad36954b29592ce463254179c3043697678481f
- https://git.kernel.org/stable/c/fe58f457ad8d0a2bef4e053cfecca4b5cd266b1a
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.