Home

Description

In the Linux kernel, the following vulnerability has been resolved: tracing: Add NULL pointer check to trigger_data_free() If trigger_data_alloc() fails and returns NULL, event_hist_trigger_parse() jumps to the out_free error path. While kfree() safely handles a NULL pointer, trigger_data_free() does not. This causes a NULL pointer dereference in trigger_data_free() when evaluating data->cmd_ops->set_filter. Fix the problem by adding a NULL pointer check to trigger_data_free(). The problem was found by an experimental code review agent based on gemini-3.1-pro while reviewing backports into v6.18.y.

PUBLISHED Reserved 2026-01-13 | Published 2026-03-25 | Updated 2026-05-11 | Assigner Linux

Product status

Default status
unaffected

c10f0efe57728508d796ae4ba7abe4c14ec3d8ef (git) before 13dcd9269e225e4c4ceabdaeebe2ce4661b54c6e
affected

7e6556e9329bc484e9dcdab6e346d959267c0636 (git) before 59c15b9cc453b74beb9f04c6c398717e73612dc3
affected

9b0513905e0598b9f8cfccab8e47497aed5d935d (git) before 42b380f97d65e76e7b310facd525f730272daf57
affected

335dfe4bc6368e70e8c15419375cf609c4f85558 (git) before 2ce8ece5a78da67834db7728edc801889a64f643
affected

e42efbe9754da78eafe11f6bd3ca9c8a094a752a (git) before 477469223b2b840f436ce204333de87cb17e5d93
affected

0550069cc25f513ce1f109c88f7c1f01d63297db (git) before 457965c13f0837a289c9164b842d0860133f6274
affected

Default status
unaffected

6.1.165 (semver) before 6.1.167
affected

6.6.128 (semver) before 6.6.130
affected

6.12.75 (semver) before 6.12.77
affected

6.18.14 (semver) before 6.18.17
affected

6.19.4 (semver) before 6.19.7
affected

References

git.kernel.org/...c/13dcd9269e225e4c4ceabdaeebe2ce4661b54c6e

git.kernel.org/...c/59c15b9cc453b74beb9f04c6c398717e73612dc3

git.kernel.org/...c/42b380f97d65e76e7b310facd525f730272daf57

git.kernel.org/...c/2ce8ece5a78da67834db7728edc801889a64f643

git.kernel.org/...c/477469223b2b840f436ce204333de87cb17e5d93

git.kernel.org/...c/457965c13f0837a289c9164b842d0860133f6274

cve.org (CVE-2026-23309)

nvd.nist.gov (CVE-2026-23309)

Download JSON