PT-2026-104874 · Azure Linux · Kernel

Published

2026-09-24

·

Updated

2026-09-24

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
perf/x86/intel/pt: Fix stop/start with no update
If pt event stop() is called without PERF EF UPDATE flag, then perf aux output end() is not called. A subsequent call to pt event start() will call perf aux output begin() again which violates the rule against nesting and triggers a WARNING in perf aux output begin().
Originally, pt event stop() was never called without PERF EF UPDATE, because the only code paths to do so are from event overflow, and Intel PT does not do that.
However the introduction of group throttling by commit 9734e25fbf5ae ("perf: Fix the throttle logic for a group") meant that an Intel PT event could be throttled if it was part of a group. Throttling calls PMU ->stop() / ->start() callbacks without flags.
An example is when AUX area sampling is used. The following commands hit the issue:
echo 10000 > /proc/sys/kernel/perf event max sample rate
perf record -F32000 --aux-sample -e '{intel pt//u,cycles:u}' -- bash -c 'for i in seq 1 100000 ; do true ; done'
Use PERF HES UPTODATE to track whether perf aux output begin() and perf aux output end() are balanced. A cleared PERF HES UPTODATE bit indicates that an AUX output context is still open.
Amend pt event start() / pt event stop() accordingly so that begin/end stay balanced:
  • In non-snapshot mode, stop() always closes the buffer (the buffer may have run out of space, and that accounting is done by the update), so a following start() opens a fresh one as before.
  • In snapshot/overwrite mode, stop() without PERF EF UPDATE leaves the buffer open so that pt event snapshot aux() can still copy from it, and start() then only re-enables tracing instead of calling perf aux output begin() again.
Note that pt event del() calls pt event stop() with PERF EF UPDATE flag set (as is required by the documentation), so a final call to perf aux output end() is assured.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-103631

Affected Products

Kernel