In the Linux kernel, the following vulnerability has been resolved:
tracing: Fix retry exhaustion in simple ring buffer reader swap
simple_ring_buffer_swap_reader_page() starts with retry set to 8 and
post-decrements it only after a failed link replacement. On the final
attempt, a successful replacement leaves retry at zero, while a failed
replacement leaves it at -1.
The current !retry test reverses both outcomes. It returns an error after
a successful final replacement, leaving the link update complete but the
reader bookkeeping unfinished. After a failed final replacement, it
falls through and updates the head and reader pointers as though the
replacement succeeded, which can corrupt the ring.
Treat only a negative counter as exhaustion and return the documented
-EBUSY error.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-11 20:20
Updated : 2026-09-13 07:17
NVD link : CVE-2026-89748
Mitre link : CVE-2026-89748
CVE.ORG link : CVE-2026-89748
JSON object : View
Products Affected
No product.
CWE
No CWE.
