{"id":"CVE-2026-97960","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nperf/x86/intel: Prevent drain_pebs() reentry\n\nThe PEBS buffer is shared by all events on a CPU, so drain_pebs() must\nnot be reentered","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nperf/x86/intel: Prevent drain_pebs() reentry\n\nThe PEBS buffer is shared by all events on a CPU, so drain_pebs() must\nnot be reentered. If so, one instance may observe s…","severity":"none","vendor":"Linux","product":"Linux","affected":["Linux >= b752ea0c28e3f7f0aaaad6abf84f735eebc37a60 < a5fe19dd8b3ed5fad6e5e0f0c58c7245043ee4af","Linux >= b752ea0c28e3f7f0aaaad6abf84f735eebc37a60 < c55599c0ec2aa020e41a0599c3044c56d8a2e7d9","Linux >= b752ea0c28e3f7f0aaaad6abf84f735eebc37a60 < a56c03a397e2cd0c4cf8da96dcd6214f7d0e7d8c","Linux a9165207b2b07415eeb01b3ac8bb84976ec96984","Linux >= 6.3.7 < 6.4","Linux 6.4"],"published":"2026-09-25","updated":"2026-09-25","sourceUpdated":"2026-09-25T11:17:23.720","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-97960","references":[{"url":"https://git.kernel.org/stable/c/a56c03a397e2cd0c4cf8da96dcd6214f7d0e7d8c","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a5fe19dd8b3ed5fad6e5e0f0c58c7245043ee4af","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c55599c0ec2aa020e41a0599c3044c56d8a2e7d9","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-25T11:06:38.875Z","slug":"CVE-2026-97960","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nperf/x86/intel: Prevent drain_pebs() reentry\n\nThe PEBS buffer is shared by all events on a CPU, so drain_pebs() must\nnot be reentered. If so, one instance may observe stale buffer state and\npotentially access out-of-bound memory.\n\nMost invocations happen in NMI context, which naturally prevents reentry.\nHowever, drain_pebs() is also reachable from process context via\nintel_pmu_drain_pebs_buffer().\n\nIn those paths, the PMU is often already disabled, but not guaranteed.\nFor example, __intel_pmu_pebs_disable() only disables the target counter,\nso other active counters can still raise a PMI and interrupt an in-flight\ndrain_pebs(). Here is an example,\n\n__perf_addr_filters_adjust()\n  perf_event_stop()\n    __perf_event_stop()\n      x86_pmu_stop() (event->pmu->stop)\n        intel_pmu_disable_event()\n          intel_pmu_pebs_disable()\n            __intel_pmu_pebs_disable()\n              intel_pmu_drain_large_pebs()\n                intel_pmu_drain_pebs_buffer()\n\nIntroduce __intel_pmu_quiesce() and __intel_pmu_resume() helpers and\nuse them in intel_pmu_drain_large_pebs() to disable the full PMU\naround the intel_pmu_drain_pebs_buffer() call, preventing reentry.\n\nAlso add a warning in intel_pmu_drain_pebs_buffer() when the full PMU is\nnot disabled.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}