{"id":"CVE-2026-98117","published":"2026-09-25T11:17:42.920","lastModified":"2026-09-25T11:17:42.920","description":"In the Linux kernel, the following vulnerability has been resolved:\n\ncachefiles: Fix potential UAF/KASAN warning\n\nCurrently, trace_cachefiles_coherency() is being passed a pointer to a\n__be64 lain over the coherency data in struct cachefiles_xattr so that it\ncan display the first 8 bytes.  However, the data is of variable length and\ncould even be 0 bytes.  This could lead to a UAF or KASAN warning.\n\nFix this by making sure the buffer has room for at least 8 bytes and that\nthose 8 bytes are pre-cleared.\n\nFurther, those bytes are not 8-byte aligned, so fix the tracepoint to\nextract the data as four 2-byte words (they are 2-byte aligned) and\nreassemble the __be64.  The compiler will convert this into a single 8-byte\nload where the CPU supports it.","cvssScore":null,"cvssSeverity":null,"cvssVector":null,"cwes":[],"vendors":[],"products":[],"references":[{"url":"https://git.kernel.org/stable/c/68d459e6e609c31f96a203dd6eec60c634f155e1","tags":[]},{"url":"https://git.kernel.org/stable/c/93488ea378b4427598cace558236c110515d743b","tags":[]},{"url":"https://git.kernel.org/stable/c/a67632c8c2688d6e0091529bcefe54bc5ee80e9b","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}