-
CVE-2026-97960
- EPSS 0.17%
- Veröffentlicht 25.09.2026 10:23:04
- Zuletzt bearbeitet 25.09.2026 11:17:23
- Erkennungen
perf/x86/intel: Prevent drain_pebs() reentry
In the Linux kernel, the following vulnerability has been resolved:
perf/x86/intel: Prevent drain_pebs() reentry
The PEBS buffer is shared by all events on a CPU, so drain_pebs() must
not be reentered. If so, one instance may observe stale buffer state and
potentially access out-of-bound memory.
Most invocations happen in NMI context, which naturally prevents reentry.
However, drain_pebs() is also reachable from process context via
intel_pmu_drain_pebs_buffer().
In those paths, the PMU is often already disabled, but not guaranteed.
For example, __intel_pmu_pebs_disable() only disables the target counter,
so other active counters can still raise a PMI and interrupt an in-flight
drain_pebs(). Here is an example,
__perf_addr_filters_adjust()
perf_event_stop()
__perf_event_stop()
x86_pmu_stop() (event->pmu->stop)
intel_pmu_disable_event()
intel_pmu_pebs_disable()
__intel_pmu_pebs_disable()
intel_pmu_drain_large_pebs()
intel_pmu_drain_pebs_buffer()
Introduce __intel_pmu_quiesce() and __intel_pmu_resume() helpers and
use them in intel_pmu_drain_large_pebs() to disable the full PMU
around the intel_pmu_drain_pebs_buffer() call, preventing reentry.
Also add a warning in intel_pmu_drain_pebs_buffer() when the full PMU is
not disabled.Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
b752ea0c28e3f7f0aaaad6abf84f735eebc37a60
Version <
a5fe19dd8b3ed5fad6e5e0f0c58c7245043ee4af
Status
affected
Version
b752ea0c28e3f7f0aaaad6abf84f735eebc37a60
Version <
c55599c0ec2aa020e41a0599c3044c56d8a2e7d9
Status
affected
Version
b752ea0c28e3f7f0aaaad6abf84f735eebc37a60
Version <
a56c03a397e2cd0c4cf8da96dcd6214f7d0e7d8c
Status
affected
Version
a9165207b2b07415eeb01b3ac8bb84976ec96984
Status
affected
Version
6.3.7
Version <
6.4
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
6.4
Status
affected
Version
0
Version <
6.4
Status
unaffected
Version <=
6.18.*
Version
6.18.53
Status
unaffected
Version <=
7.2.*
Version
7.2.7
Status
unaffected
Version <=
*
Version
7.3-rc3
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.17% | 0.052 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|
https://git.kernel.org/stable/c/a5fe19dd8b3ed5fad6e5e0f0c58c7245043ee4af
https://git.kernel.org/stable/c/c55599c0ec2aa020e41a0599c3044c56d8a2e7d9
https://git.kernel.org/stable/c/a56c03a397e2cd0c4cf8da96dcd6214f7d0e7d8c