« Volver al listado

CVE-2026-93181

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

perf/x86/intel/uncore: Fix uncore_box ref/unref ordering

In uncore_event_cpu_online(), uncore_box_ref() was called before uncore_change_context(). uncore_box_ref() gates on box->cpu >= 0, but box->cpu is still -1 at that point because uncore_change_context() has not run yet. As a result, the box is never initialized on the first CPU to come online in a die, leaving it permanently uninitialized in the single-CPU-per-die case.

Thus, box->refcnt is one count below the true value, and in the CPU offline path, the box will be torn down on the second-to-last CPU.

Leer descripción completaMostrar menos

In uncore_event_cpu_offline(), uncore_box_unref() was called after uncore_change_context(), so box->cpu is already -1 when the collector CPU goes offline, which prevents it from tearing down the box.

Fix by swapping the call order in both paths so that uncore_box_{ref,unref}() runs at the point where box->cpu reflects the correct context.

Move allocate_boxes() out of uncore_box_ref() to enable this reordering.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-93181",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "c74443d92f68f07c03ae242ced554b749e6c6736",
              "lessThan": "64aa1bb4017d598828c6d8cd718f43daf2a83375",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "c74443d92f68f07c03ae242ced554b749e6c6736",
              "lessThan": "174f0582e38abe03b88e15f04bfe58490f88cb19",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "arch/x86/events/intel/uncore.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.11"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.11",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "7.2.6",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "arch/x86/events/intel/uncore.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-17T17:18:14.027",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/174f0582e38abe03b88e15f04bfe58490f88cb19",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/64aa1bb4017d598828c6d8cd718f43daf2a83375",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nperf/x86/intel/uncore: Fix uncore_box ref/unref ordering\n\nIn uncore_event_cpu_online(), uncore_box_ref() was called before\nuncore_change_context().  uncore_box_ref() gates on box->cpu >= 0,\nbut box->cpu is still -1 at that point because uncore_change_context()\nhas not run yet.  As a result, the box is never initialized on the\nfirst CPU to come online in a die, leaving it permanently\nuninitialized in the single-CPU-per-die case.\n\nThus, box->refcnt is one count below the true value, and in the CPU\noffline path, the box will be torn down on the second-to-last CPU.\n\nIn uncore_event_cpu_offline(), uncore_box_unref() was called after\nuncore_change_context(), so box->cpu is already -1 when the collector\nCPU goes offline, which prevents it from tearing down the box.\n\nFix by swapping the call order in both paths so that\nuncore_box_{ref,unref}() runs at the point where box->cpu reflects\nthe correct context.\n\nMove allocate_boxes() out of uncore_box_ref() to enable this\nreordering."
    }
  ],
  "lastModified": "2026-09-17T17:18:14.027",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}