CVE-2026-23309 PUBLISHED

tracing: Add NULL pointer check to trigger_data_free()

Assigner: Linux
Reserved: 13.01.2026 Published: 25.03.2026 Updated: 25.03.2026

In the Linux kernel, the following vulnerability has been resolved:

tracing: Add NULL pointer check to trigger_data_free()

If trigger_data_alloc() fails and returns NULL, event_hist_trigger_parse() jumps to the out_free error path. While kfree() safely handles a NULL pointer, trigger_data_free() does not. This causes a NULL pointer dereference in trigger_data_free() when evaluating data->cmd_ops->set_filter.

Fix the problem by adding a NULL pointer check to trigger_data_free().

The problem was found by an experimental code review agent based on gemini-3.1-pro while reviewing backports into v6.18.y.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from c10f0efe57728508d796ae4ba7abe4c14ec3d8ef to 13dcd9269e225e4c4ceabdaeebe2ce4661b54c6e (excl.)
  • affected from 7e6556e9329bc484e9dcdab6e346d959267c0636 to 59c15b9cc453b74beb9f04c6c398717e73612dc3 (excl.)
  • affected from 9b0513905e0598b9f8cfccab8e47497aed5d935d to 42b380f97d65e76e7b310facd525f730272daf57 (excl.)
  • affected from 335dfe4bc6368e70e8c15419375cf609c4f85558 to 2ce8ece5a78da67834db7728edc801889a64f643 (excl.)
  • affected from e42efbe9754da78eafe11f6bd3ca9c8a094a752a to 477469223b2b840f436ce204333de87cb17e5d93 (excl.)
  • affected from 0550069cc25f513ce1f109c88f7c1f01d63297db to 457965c13f0837a289c9164b842d0860133f6274 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 7.0-rc1 is affected
  • unaffected from 0 to 7.0-rc1 (excl.)
  • unaffected from 6.1.167 to 6.1.* (incl.)
  • unaffected from 6.6.130 to 6.6.* (incl.)
  • unaffected from 6.12.77 to 6.12.* (incl.)
  • unaffected from 6.18.17 to 6.18.* (incl.)
  • unaffected from 6.19.7 to 6.19.* (incl.)
  • unaffected from 7.0-rc3 to * (incl.)

References