cbcvebase.
CVE-2026-23309
published 2026-03-25

CVE-2026-23309: In the Linux kernel, the following vulnerability has been resolved: tracing: Add NULL pointer check to trigger_data_free() If trigger_data_alloc() fails and…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.12%
2.4th percentile
In the Linux kernel, the following vulnerability has been resolved: tracing: Add NULL pointer check to trigger_data_free() If trigger_data_alloc() fails and returns NULL, event_hist_trigger_parse() jumps to the out_free error path. While kfree() safely handles a NULL pointer, trigger_data_free() does not. This causes a NULL pointer dereference in trigger_data_free() when evaluating data->cmd_ops->set_filter. Fix the problem by adding a NULL pointer check to trigger_data_free(). The problem was found by an experimental code review agent based on gemini-3.1-pro while reviewing backports into v6.18.y.

Affected

24 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.19.8-1 (forky)linux 6.19.8-1 (forky)
linuxlinux>= 0550069cc25f513ce1f109c88f7c1f01d63297db < 457965c13f0837a289c9164b842d0860133f6274457965c13f0837a289c9164b842d0860133f6274
linuxlinux>= 335dfe4bc6368e70e8c15419375cf609c4f85558 < 2ce8ece5a78da67834db7728edc801889a64f6432ce8ece5a78da67834db7728edc801889a64f643
linuxlinux>= 6.1.165 < 6.1.1676.1.167
linuxlinux>= 6.12.75 < 6.12.776.12.77
linuxlinux>= 6.18.14 < 6.18.176.18.17
linuxlinux>= 6.19.4 < 6.19.76.19.7
linuxlinux>= 6.6.128 < 6.6.1306.6.130
linuxlinux>= 7e6556e9329bc484e9dcdab6e346d959267c0636 < 59c15b9cc453b74beb9f04c6c398717e73612dc359c15b9cc453b74beb9f04c6c398717e73612dc3
linuxlinux>= 9b0513905e0598b9f8cfccab8e47497aed5d935d < 42b380f97d65e76e7b310facd525f730272daf5742b380f97d65e76e7b310facd525f730272daf57
linuxlinux>= c10f0efe57728508d796ae4ba7abe4c14ec3d8ef < 13dcd9269e225e4c4ceabdaeebe2ce4661b54c6e13dcd9269e225e4c4ceabdaeebe2ce4661b54c6e
linuxlinux>= e42efbe9754da78eafe11f6bd3ca9c8a094a752a < 477469223b2b840f436ce204333de87cb17e5d93477469223b2b840f436ce204333de87cb17e5d93
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.19.8-16.19.8-1
linuxlinux_kernel>= 0 < 6.1.1676.1.167
linuxlinux_kernel>= 6.1.165 < 6.1.1676.1.167
linuxlinux_kernel>= 6.12.75 < 6.12.776.12.77
linuxlinux_kernel>= 6.13.0 < 6.18.176.18.17
linuxlinux_kernel>= 6.18.14 < 6.18.176.18.17
linuxlinux_kernel>= 6.19.0 < 6.19.76.19.7
linuxlinux_kernel>= 6.19.4 < 6.19.76.19.7
linuxlinux_kernel>= 6.2.0 < 6.6.1306.6.130
linuxlinux_kernel>= 6.6.128 < 6.6.1306.6.130
linuxlinux_kernel>= 6.7.0 < 6.12.776.12.77
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.