« Volver al listado

CVE-2026-97499

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

coresight: perf: Retrieve path and source from event data

ETM perf callbacks currently use the per-CPU csdev_src pointer, which can race with updates during device registration and unregistration.

The AUX setup already builds and stores the path in the event data. Use this path to retrieve the source instead of csdev_src to avoid the race.

Export coresight_get_source() and add etm_event_get_ctxt_path() to retrieve the context's path and its source with READ_ONCE() / WRITE_ONCE() accessors. Give the comments to explain why this approach is safe when pause or resume callbacks preempt the disable callback (e.g. via NMI).

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-97499",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "0bcbf2e30ff2271b54f54c8697a185f7d86ec6e4",
              "lessThan": "0f4cb08f30011b7625a4fba668fa5c36da5e6637",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "0bcbf2e30ff2271b54f54c8697a185f7d86ec6e4",
              "lessThan": "f37bc31447c0ddafedb25e3c4a4f4e2284034247",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/hwtracing/coresight/coresight-core.c",
            "drivers/hwtracing/coresight/coresight-etm-perf.c",
            "drivers/hwtracing/coresight/coresight-priv.h"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4.6"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "4.6",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.18.53",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/hwtracing/coresight/coresight-core.c",
            "drivers/hwtracing/coresight/coresight-etm-perf.c",
            "drivers/hwtracing/coresight/coresight-priv.h"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-24T17:17:27.630",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/0f4cb08f30011b7625a4fba668fa5c36da5e6637",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/f37bc31447c0ddafedb25e3c4a4f4e2284034247",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncoresight: perf: Retrieve path and source from event data\n\nETM perf callbacks currently use the per-CPU csdev_src pointer, which\ncan race with updates during device registration and unregistration.\n\nThe AUX setup already builds and stores the path in the event data.\nUse this path to retrieve the source instead of csdev_src to avoid\nthe race.\n\nExport coresight_get_source() and add etm_event_get_ctxt_path() to\nretrieve the context's path and its source with READ_ONCE() /\nWRITE_ONCE() accessors. Give the comments to explain why this\napproach is safe when pause or resume callbacks preempt the disable\ncallback (e.g. via NMI)."
    }
  ],
  "lastModified": "2026-09-28T06:16:35.893",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}