Linux hwe edge: In the Linux kernel, the following vulnerability has been resolved: ftrace: Do not over-allocate ftrace memory The pg_remaining calculation in… (CVE-2026-23052)
A vulnerability in the Linux kernel's ftrace subsystem involving incorrect memory allocation calculations has been resolved. The issue arises because the calculation of remaining pages underestimates available capacity when PAGE_SIZE is not a multiple of ENTRY_SIZE, leading to over-allocation of ftrace memory and triggering kernel warnings. This flaw could potentially be exploited to compromise the system. The vulnerability affects multiple Linux kernel versions prior to 6.17.0-1021.21~24.04.1 and related builds. Official patches are available from Ubuntu, and users are advised to update and reboot to apply fixes. Due to an ABI change, recompilation of third-party kernel modules may be necessary after updating. The severity is assessed as medium based on the impact described.
AI Analysis
Technical Summary
The Linux kernel vulnerability CVE-2026-23052 involves the ftrace subsystem's memory allocation logic. Specifically, the pg_remaining calculation in ftrace_process_locs() assumes that ENTRIES_PER_PAGE multiplied by 2^order equals the actual capacity of the allocated page group. However, because ENTRIES_PER_PAGE is computed via integer division (PAGE_SIZE / ENTRY_SIZE), when PAGE_SIZE is not a multiple of ENTRY_SIZE, the actual capacity is larger than assumed. This causes pg_remaining to be underestimated, resulting in excessive memory allocation and kernel warnings. A similar issue in ftrace_allocate_records() can also cause over-allocation. These flaws have been fixed in Linux kernel versions 6.17.0 and later. Ubuntu has released security updates addressing this and other kernel vulnerabilities, requiring system updates and reboots. The update also requires recompilation of third-party kernel modules due to ABI changes.
Potential Impact
The vulnerability can cause the Linux kernel to allocate more memory than intended in the ftrace subsystem, potentially leading to kernel warnings and instability. While the advisory notes that an attacker could possibly use these issues to compromise the system, no known exploits are reported in the wild. The impact is considered medium severity, reflecting the potential for system compromise but no confirmed active exploitation.
Mitigation Recommendations
Official patches are available and have been released by Ubuntu for affected Linux kernel versions. Users should apply the updates promptly and reboot their systems to ensure the fixes take effect. Due to an ABI change in the kernel updates, recompilation and reinstallation of all third-party kernel modules are required. Follow the vendor's update instructions carefully to fully remediate the vulnerability.
Linux hwe edge: In the Linux kernel, the following vulnerability has been resolved: ftrace: Do not over-allocate ftrace memory The pg_remaining calculation in… (CVE-2026-23052)
Description
A vulnerability in the Linux kernel's ftrace subsystem involving incorrect memory allocation calculations has been resolved. The issue arises because the calculation of remaining pages underestimates available capacity when PAGE_SIZE is not a multiple of ENTRY_SIZE, leading to over-allocation of ftrace memory and triggering kernel warnings. This flaw could potentially be exploited to compromise the system. The vulnerability affects multiple Linux kernel versions prior to 6.17.0-1021.21~24.04.1 and related builds. Official patches are available from Ubuntu, and users are advised to update and reboot to apply fixes. Due to an ABI change, recompilation of third-party kernel modules may be necessary after updating. The severity is assessed as medium based on the impact described.
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Linux kernel vulnerability CVE-2026-23052 involves the ftrace subsystem's memory allocation logic. Specifically, the pg_remaining calculation in ftrace_process_locs() assumes that ENTRIES_PER_PAGE multiplied by 2^order equals the actual capacity of the allocated page group. However, because ENTRIES_PER_PAGE is computed via integer division (PAGE_SIZE / ENTRY_SIZE), when PAGE_SIZE is not a multiple of ENTRY_SIZE, the actual capacity is larger than assumed. This causes pg_remaining to be underestimated, resulting in excessive memory allocation and kernel warnings. A similar issue in ftrace_allocate_records() can also cause over-allocation. These flaws have been fixed in Linux kernel versions 6.17.0 and later. Ubuntu has released security updates addressing this and other kernel vulnerabilities, requiring system updates and reboots. The update also requires recompilation of third-party kernel modules due to ABI changes.
Potential Impact
The vulnerability can cause the Linux kernel to allocate more memory than intended in the ftrace subsystem, potentially leading to kernel warnings and instability. While the advisory notes that an attacker could possibly use these issues to compromise the system, no known exploits are reported in the wild. The impact is considered medium severity, reflecting the potential for system compromise but no confirmed active exploitation.
Mitigation Recommendations
Official patches are available and have been released by Ubuntu for affected Linux kernel versions. Users should apply the updates promptly and reboot their systems to ensure the fixes take effect. Due to an ABI change in the kernel updates, recompilation and reinstallation of all third-party kernel modules are required. Follow the vendor's update instructions carefully to fully remediate the vulnerability.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-qvpg-9fvc-x6cv
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-23052"]
Threat ID: 6a498a7827e9c7971936efec
Added to database: 07/04/2026, 22:34:32 UTC
Last enriched: 08/22/2026, 21:33:15 UTC
Last updated: 09/10/2026, 19:36:52 UTC
Views: 68
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.