---
id: CVE-2026-64402
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  coresight: ultrasoc-smb: Fix OOB write in smb_sync_perf_buffer()

  When the SMB sink is used as a perf AUX sink, smb_update_buffer() calls
  smb_sync_perf_buffer() to copy…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  coresight: ultrasoc-smb: Fix OOB write in smb_sync_perf_buffer()

  When the SMB sink is used as a perf AUX sink, smb_update_buffer() calls
  smb_sync_perf_buffer() to copy…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-787
vendor: linux
product: linux_kernel
affected:
  - 'linux_kernel >= 6.3, < 6.6.145'
  - 'linux_kernel >= 6.7, < 6.12.96'
  - 'linux_kernel >= 6.13, < 6.18.39'
  - 'linux_kernel >= 6.19, < 7.1.4'
patched:
  - linux_kernel 7.1.4
published: '2026-07-25'
updated: '2026-09-04'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-64402'
references:
  - url: 'https://git.kernel.org/stable/c/38dbc8db8341ccdf8e1e1a067453d33ad751864b'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/4c5a0a946373da99a80398289b28845b5ae40cd1'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/661a019ac0413ecec9e5d1dfcc12fbca8e78d5fb'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/98495b5a4d77dd22e106f462b76e1093a55b29a7'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/daf6246ab988fc8bdc82ad7c8d0b1c182d11b15f'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
epss: 0.00129
epssPercentile: 0.02861
ingestedAt: '2026-09-05T13:39:57.942Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

coresight: ultrasoc-smb: Fix OOB write in smb_sync_perf_buffer()

When the SMB sink is used as a perf AUX sink, smb_update_buffer() calls
smb_sync_perf_buffer() to copy hardware trace data into the perf AUX ring
buffer pages. It derives pg_idx = head >> PAGE_SHIFT from @head, which is
handle->head, and indexes dst_pages[pg_idx]. The pg_idx %= nr_pages
normalization is only applied after the first loop iteration.

This leaves the initial page index underived from the buffer size, which
can result in an out-of-bounds write past dst_pages[] when head exceeds
the AUX buffer size.

Normalize head modulo the AUX buffer size before deriving the page index
and offset, mirroring tmc_etr_sync_perf_buffer().

## Affected

- `linux_kernel >= 6.3, < 6.6.145`
- `linux_kernel >= 6.7, < 6.12.96`
- `linux_kernel >= 6.13, < 6.18.39`
- `linux_kernel >= 6.19, < 7.1.4`

## Remediation

Upgrade past the affected range:

- `linux_kernel 7.1.4`
