CVE-2026-43409

Source
https://cve.org/CVERecord?id=CVE-2026-43409
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-43409.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-43409
Downstream
Published
2026-05-08T14:21:48.239Z
Modified
2026-07-11T03:54:32.189527507Z
Summary
kprobes: avoid crash when rmmod/insmod after ftrace killed
Details

In the Linux kernel, the following vulnerability has been resolved:

kprobes: avoid crash when rmmod/insmod after ftrace killed

After we hit ftrace is killed by some errors, the kernel crash if we remove modules in which kprobe probes.

BUG: unable to handle page fault for address: fffffbfff805000d PGD 817fcc067 P4D 817fcc067 PUD 817fc8067 PMD 101555067 PTE 0 Oops: Oops: 0000 [#1] SMP KASAN PTI CPU: 4 UID: 0 PID: 2012 Comm: rmmod Tainted: G W OE Tainted: [W]=WARN, [O]=OOTMODULE, [E]=UNSIGNEDMODULE RIP: 0010:kprobesmodulecallback+0x89/0x790 RSP: 0018:ffff88812e157d30 EFLAGS: 00010a02 RAX: 1ffffffff805000d RBX: dffffc0000000000 RCX: ffffffff86a8de90 RDX: ffffed1025c2af9b RSI: 0000000000000008 RDI: ffffffffc0280068 RBP: 0000000000000000 R08: 0000000000000001 R09: ffffed1025c2af9a R10: ffff88812e157cd7 R11: 205d323130325420 R12: 0000000000000002 R13: ffffffffc0290488 R14: 0000000000000002 R15: ffffffffc0280040 FS: 00007fbc450dd740(0000) GS:ffff888420331000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: fffffbfff805000d CR3: 000000010f624000 CR4: 00000000000006f0 Call Trace: <TASK> notifiercallchain+0xc6/0x280 blockingnotifiercall_chain+0x60/0x90 _dosysdeletemodule.constprop.0+0x32a/0x4e0 dosyscall64+0x5d/0xfa0 entrySYSCALL64afterhwframe+0x76/0x7e

This is because the kprobe on ftrace does not correctly handles the kprobeftracedisabled flag set by ftrace_kill().

To prevent this error, check kprobeftracedisabled in __disarmkprobeftrace() and skip all ftrace related operations.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/43xxx/CVE-2026-43409.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
ae6aa16fdc163afe6b04b6c073ad4ddd4663c03b
Fixed
8b6767e4141b2a42745b544d4555cf1614ba1a2d
Fixed
b0ca81616a010807e91fc31db9be242b96326adc
Fixed
cae928e3178c75602c21d67e21255d73e7e9ed4f
Fixed
9edc79d664832a842012ad105b1521c1a3c35ab3
Fixed
e113f0b46d19626ec15388bcb91432c9a4fd6261

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-43409.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.7.0
Fixed
6.6.130
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.78
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.19
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
6.19.9

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-43409.json"