PT-2026-106597 · Linux · Linux
CVE-2026-98268
·
Published
2026-10-06
·
Updated
2026-10-06
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
perf: Fix null pointer access in is include guest event()
A typical module unload occurring event when there is an active perf
connection leads to freeing of the pmu pointer. The call log is something
like:
..
pmu detach event
pmu detach event
pmu detach events
perf pmu unregister
..
pmu detach event() sets event->pmu to null. When the perf connection
finally is closed, the following stack trace is observed:
Oops: general protection fault, kernel NULL pointer dereference
...
RIP: 0010: free event+0x3e/0x370
...
Call Trace:
...
perf event release kernel+0x260/0x2d0
perf release+0x12/0x20
A call to mediated pmu unaccount event() inside free event() is the root
cause of this crash. Adding a check inside is include guest event() ensures
we don't accidentally access a null pmu ptr. In addition to this, we will
now call mediated pmu unaccount event() before clearing the pmu ptr so that
nr include guest events counts are maintained correctly.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux