HomeDefectsLIN1023-32715
Fixed

LIN1023-32715 : Security Advisory - linux - CVE-2026-97960

Created: Sep 25, 2026    Updated: Oct 2, 2026
Resolved Date: Oct 2, 2026
Found In Version: 10.23.30.2
Fix Version: 10.23.30.9
Severity: Standard
Applicable for: Wind River Linux LTS 23
Component/s: Kernel

Description

In the Linux kernel, the following vulnerability has been resolved:  perf/x86/intel: Prevent drain_pebs() reentry  The PEBS buffer is shared by all events on a CPU, so drain_pebs() must not be reentered. If so, one instance may observe stale buffer state and potentially access out-of-bound memory.  Most invocations happen in NMI context, which naturally prevents reentry. However, drain_pebs() is also reachable from process context via intel_pmu_drain_pebs_buffer().  In those paths, the PMU is often already disabled, but not guaranteed. For example, __intel_pmu_pebs_disable() only disables the target counter, so other active counters can still raise a PMI and interrupt an in-flight drain_pebs(). Here is an example,  __perf_addr_filters_adjust()   perf_event_stop()     __perf_event_stop()       x86_pmu_stop() (event->pmu->stop)         intel_pmu_disable_event()           intel_pmu_pebs_disable()             __intel_pmu_pebs_disable()               intel_pmu_drain_large_pebs()                 intel_pmu_drain_pebs_buffer()  Introduce __intel_pmu_quiesce() and __intel_pmu_resume() helpers and use them in intel_pmu_drain_large_pebs() to disable the full PMU around the intel_pmu_drain_pebs_buffer() call, preventing reentry.  Also add a warning in intel_pmu_drain_pebs_buffer() when the full PMU is not disabled.
Data source: kernel.org (416baaa9-dc9f-4396-8d5f-8c081fb06d67)