PT-2026-98624 · Linux · Linux

CVE-2026-97960

·

Published

2026-09-25

·

Updated

2026-09-25

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
perf/x86/intel: Prevent drain pebs() reentry
The PEBS buffer is shared by all events on a CPU, so drain pebs() must not be reentered. If so, one instance may observe stale buffer state and potentially access out-of-bound memory.
Most invocations happen in NMI context, which naturally prevents reentry. However, drain pebs() is also reachable from process context via intel pmu drain pebs buffer().
In those paths, the PMU is often already disabled, but not guaranteed. For example, intel pmu pebs disable() only disables the target counter, so other active counters can still raise a PMI and interrupt an in-flight drain pebs(). Here is an example,
perf addr filters adjust() perf event stop() perf event stop() x86 pmu stop() (event->pmu->stop) intel pmu disable event() intel pmu pebs disable() intel pmu pebs disable() intel pmu drain large pebs() intel pmu drain pebs buffer()
Introduce intel pmu quiesce() and intel pmu resume() helpers and use them in intel pmu drain large pebs() to disable the full PMU around the intel pmu drain pebs buffer() call, preventing reentry.
Also add a warning in intel pmu drain pebs buffer() when the full PMU is not disabled.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-97960

Affected Products

Linux