« Volver al listado

CVE-2026-97960

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

perf/x86/intel: Prevent drain_pebs() reentry

The PEBS buffer is shared by all events on a CPU, so drain_pebs() must not be reentered. If so, one instance may observe stale buffer state and potentially access out-of-bound memory.

Most invocations happen in NMI context, which naturally prevents reentry. However, drain_pebs() is also reachable from process context via intel_pmu_drain_pebs_buffer().

In those paths, the PMU is often already disabled, but not guaranteed. For example, __intel_pmu_pebs_disable() only disables the target counter, so other active counters can still raise a PMI and interrupt an in-flight drain_pebs(). Here is an example,

Leer descripción completaMostrar menos

Introduce __intel_pmu_quiesce() and __intel_pmu_resume() helpers and use them in intel_pmu_drain_large_pebs() to disable the full PMU around the intel_pmu_drain_pebs_buffer() call, preventing reentry.

Also add a warning in intel_pmu_drain_pebs_buffer() when the full PMU is not disabled.

Detalles técnicos trazas, registros y código del informe original
__perf_addr_filters_adjust()
  perf_event_stop()
    __perf_event_stop()
      x86_pmu_stop() (event->pmu->stop)
        intel_pmu_disable_event()
          intel_pmu_pebs_disable()
            __intel_pmu_pebs_disable()
              intel_pmu_drain_large_pebs()
                intel_pmu_drain_pebs_buffer()

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-97960",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "b752ea0c28e3f7f0aaaad6abf84f735eebc37a60",
              "lessThan": "a5fe19dd8b3ed5fad6e5e0f0c58c7245043ee4af",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "b752ea0c28e3f7f0aaaad6abf84f735eebc37a60",
              "lessThan": "c55599c0ec2aa020e41a0599c3044c56d8a2e7d9",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "b752ea0c28e3f7f0aaaad6abf84f735eebc37a60",
              "lessThan": "a56c03a397e2cd0c4cf8da96dcd6214f7d0e7d8c",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "a9165207b2b07415eeb01b3ac8bb84976ec96984",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "6.3.7",
              "lessThan": "6.4",
              "versionType": "semver"
            }
          ],
          "programFiles": [
            "arch/x86/events/intel/core.c",
            "arch/x86/events/intel/ds.c",
            "arch/x86/events/perf_event.h"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.4"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.4",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.18.53",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.7",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc3",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "arch/x86/events/intel/core.c",
            "arch/x86/events/intel/ds.c",
            "arch/x86/events/perf_event.h"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-25T11:17:23.720",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/a56c03a397e2cd0c4cf8da96dcd6214f7d0e7d8c",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/a5fe19dd8b3ed5fad6e5e0f0c58c7245043ee4af",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/c55599c0ec2aa020e41a0599c3044c56d8a2e7d9",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nperf/x86/intel: Prevent drain_pebs() reentry\n\nThe PEBS buffer is shared by all events on a CPU, so drain_pebs() must\nnot be reentered. If so, one instance may observe stale buffer state and\npotentially access out-of-bound memory.\n\nMost invocations happen in NMI context, which naturally prevents reentry.\nHowever, drain_pebs() is also reachable from process context via\nintel_pmu_drain_pebs_buffer().\n\nIn those paths, the PMU is often already disabled, but not guaranteed.\nFor example, __intel_pmu_pebs_disable() only disables the target counter,\nso other active counters can still raise a PMI and interrupt an in-flight\ndrain_pebs(). Here is an example,\n\n__perf_addr_filters_adjust()\n  perf_event_stop()\n    __perf_event_stop()\n      x86_pmu_stop() (event->pmu->stop)\n        intel_pmu_disable_event()\n          intel_pmu_pebs_disable()\n            __intel_pmu_pebs_disable()\n              intel_pmu_drain_large_pebs()\n                intel_pmu_drain_pebs_buffer()\n\nIntroduce __intel_pmu_quiesce() and __intel_pmu_resume() helpers and\nuse them in intel_pmu_drain_large_pebs() to disable the full PMU\naround the intel_pmu_drain_pebs_buffer() call, preventing reentry.\n\nAlso add a warning in intel_pmu_drain_pebs_buffer() when the full PMU is\nnot disabled."
    }
  ],
  "lastModified": "2026-09-25T11:17:23.720",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}