A proposed Linux kernel patch addresses a potential use-after-free condition in the fprobe_return() tracing path on systems configured with preemptible RCU. The return handler previously disabled preemption, which prevents task migration but does not create the RCU read-side critical section needed to prevent unregister_fprobe() from freeing an fprobe object while a return callback still references it.
The patch replaces the preemption-only protection with guard(rcu)(), bringing the return path in line with fprobe’s entry handling and deferring object reclamation until active callbacks complete. The change remains under upstream review; no CVE, confirmed affected-version list, public proof of concept, or evidence of unprivileged exploitation has been reported.

See affected versions and whether adversaries are exploiting it.
1 event from the most recent confirmed update back to the earliest known activity.
A Linux kernel patch was proposed to protect fprobe_return() with guard(rcu)(), addressing a potential use-after-free race on preemptible RCU kernels during fprobe or asynchronous BPF multi-kprobe unregistration. The patch was under upstream review, with no CVE, public reproducer, or demonstrated exploitation reported.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.