CVE-2026-97499
In the Linux kernel, the following vulnerability has been resolved:
coresight: perf: Retrieve path and source from event data
ETM perf callbacks currently use the per-CPU csdev_src pointer, which can race with updates during device registration and unregistration.
The AUX setup already builds and stores the path in the event data. Use this path to retrieve the source instead of csdev_src to avoid the race.
Export coresight_get_source() and add etm_event_get_ctxt_path() to retrieve the context's path and its source with READ_ONCE() / WRITE_ONCE() accessors. Give the comments to explain why this approach is safe when pause or resume callbacks preempt the disable callback (e.g. via NMI).
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.15%
- Percentil entre todas las CVEs puntuadas: 4
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-97499",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "0bcbf2e30ff2271b54f54c8697a185f7d86ec6e4",
"lessThan": "0f4cb08f30011b7625a4fba668fa5c36da5e6637",
"versionType": "git"
},
{
"status": "affected",
"version": "0bcbf2e30ff2271b54f54c8697a185f7d86ec6e4",
"lessThan": "f37bc31447c0ddafedb25e3c4a4f4e2284034247",
"versionType": "git"
}
],
"programFiles": [
"drivers/hwtracing/coresight/coresight-core.c",
"drivers/hwtracing/coresight/coresight-etm-perf.c",
"drivers/hwtracing/coresight/coresight-priv.h"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "4.6"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "4.6",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.18.53",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/hwtracing/coresight/coresight-core.c",
"drivers/hwtracing/coresight/coresight-etm-perf.c",
"drivers/hwtracing/coresight/coresight-priv.h"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-24T17:17:27.630",
"references": [
{
"url": "https://git.kernel.org/stable/c/0f4cb08f30011b7625a4fba668fa5c36da5e6637",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/f37bc31447c0ddafedb25e3c4a4f4e2284034247",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncoresight: perf: Retrieve path and source from event data\n\nETM perf callbacks currently use the per-CPU csdev_src pointer, which\ncan race with updates during device registration and unregistration.\n\nThe AUX setup already builds and stores the path in the event data.\nUse this path to retrieve the source instead of csdev_src to avoid\nthe race.\n\nExport coresight_get_source() and add etm_event_get_ctxt_path() to\nretrieve the context's path and its source with READ_ONCE() /\nWRITE_ONCE() accessors. Give the comments to explain why this\napproach is safe when pause or resume callbacks preempt the disable\ncallback (e.g. via NMI)."
}
],
"lastModified": "2026-09-28T06:16:35.893",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}