PT-2026-104874 · Azure Linux · Kernel
Published
2026-09-24
·
Updated
2026-09-24
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
perf/x86/intel/pt: Fix stop/start with no update
If pt event stop() is called without PERF EF UPDATE flag, then
perf aux output end() is not called. A subsequent call to pt event start()
will call perf aux output begin() again which violates the rule against
nesting and triggers a WARNING in perf aux output begin().
Originally, pt event stop() was never called without PERF EF UPDATE,
because the only code paths to do so are from event overflow, and Intel PT
does not do that.
However the introduction of group throttling by commit 9734e25fbf5ae
("perf: Fix the throttle logic for a group") meant that an Intel PT event
could be throttled if it was part of a group. Throttling calls PMU
->stop() / ->start() callbacks without flags.
An example is when AUX area sampling is used. The following commands
hit the issue:
echo 10000 > /proc/sys/kernel/perf event max sample rate
perf record -F32000 --aux-sample -e '{intel pt//u,cycles:u}'
-- bash -c 'for i in
seq 1 100000 ; do true ; done'Use PERF HES UPTODATE to track whether perf aux output begin() and
perf aux output end() are balanced. A cleared PERF HES UPTODATE bit
indicates that an AUX output context is still open.
Amend pt event start() / pt event stop() accordingly so that begin/end
stay balanced:
-
In non-snapshot mode, stop() always closes the buffer (the buffer may have run out of space, and that accounting is done by the update), so a following start() opens a fresh one as before.
-
In snapshot/overwrite mode, stop() without PERF EF UPDATE leaves the buffer open so that pt event snapshot aux() can still copy from it, and start() then only re-enables tracing instead of calling perf aux output begin() again.
Note that pt event del() calls pt event stop() with PERF EF UPDATE flag set
(as is required by the documentation), so a final call to
perf aux output end() is assured.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Kernel