{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-97960","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-25T10:18:58.206Z","datePublished":"2026-09-25T10:23:04.943Z","dateUpdated":"2026-09-25T10:23:04.943Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-25T10:23:04.943Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nperf/x86/intel: Prevent drain_pebs() reentry\n\nThe PEBS buffer is shared by all events on a CPU, so drain_pebs() must\nnot be reentered. If so, one instance may observe stale buffer state and\npotentially access out-of-bound memory.\n\nMost invocations happen in NMI context, which naturally prevents reentry.\nHowever, drain_pebs() is also reachable from process context via\nintel_pmu_drain_pebs_buffer().\n\nIn those paths, the PMU is often already disabled, but not guaranteed.\nFor example, __intel_pmu_pebs_disable() only disables the target counter,\nso other active counters can still raise a PMI and interrupt an in-flight\ndrain_pebs(). Here is an example,\n\n__perf_addr_filters_adjust()\n  perf_event_stop()\n    __perf_event_stop()\n      x86_pmu_stop() (event->pmu->stop)\n        intel_pmu_disable_event()\n          intel_pmu_pebs_disable()\n            __intel_pmu_pebs_disable()\n              intel_pmu_drain_large_pebs()\n                intel_pmu_drain_pebs_buffer()\n\nIntroduce __intel_pmu_quiesce() and __intel_pmu_resume() helpers and\nuse them in intel_pmu_drain_large_pebs() to disable the full PMU\naround the intel_pmu_drain_pebs_buffer() call, preventing reentry.\n\nAlso add a warning in intel_pmu_drain_pebs_buffer() when the full PMU is\nnot disabled."}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["arch/x86/events/intel/core.c","arch/x86/events/intel/ds.c","arch/x86/events/perf_event.h"],"versions":[{"version":"b752ea0c28e3f7f0aaaad6abf84f735eebc37a60","lessThan":"a5fe19dd8b3ed5fad6e5e0f0c58c7245043ee4af","status":"affected","versionType":"git"},{"version":"b752ea0c28e3f7f0aaaad6abf84f735eebc37a60","lessThan":"c55599c0ec2aa020e41a0599c3044c56d8a2e7d9","status":"affected","versionType":"git"},{"version":"b752ea0c28e3f7f0aaaad6abf84f735eebc37a60","lessThan":"a56c03a397e2cd0c4cf8da96dcd6214f7d0e7d8c","status":"affected","versionType":"git"},{"version":"a9165207b2b07415eeb01b3ac8bb84976ec96984","status":"affected","versionType":"git"},{"version":"6.3.7","lessThan":"6.4","status":"affected","versionType":"semver"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["arch/x86/events/intel/core.c","arch/x86/events/intel/ds.c","arch/x86/events/perf_event.h"],"versions":[{"version":"6.4","status":"affected"},{"version":"0","lessThan":"6.4","status":"unaffected","versionType":"semver"},{"version":"6.18.53","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.7","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc3","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.4","versionEndExcluding":"6.18.53"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.4","versionEndExcluding":"7.2.7"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.4","versionEndExcluding":"7.3-rc3"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.3.7"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/a5fe19dd8b3ed5fad6e5e0f0c58c7245043ee4af"},{"url":"https://git.kernel.org/stable/c/c55599c0ec2aa020e41a0599c3044c56d8a2e7d9"},{"url":"https://git.kernel.org/stable/c/a56c03a397e2cd0c4cf8da96dcd6214f7d0e7d8c"}],"title":"perf/x86/intel: Prevent drain_pebs() reentry","x_generator":{"engine":"bippy-1.2.0"}}}}