---
id: CVE-2026-97960
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  perf/x86/intel: Prevent drain_pebs() reentry

  The PEBS buffer is shared by all events on a CPU, so drain_pebs() must
  not be reentered
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  perf/x86/intel: Prevent drain_pebs() reentry

  The PEBS buffer is shared by all events on a CPU, so drain_pebs() must
  not be reentered. If so, one instance may observe s…
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= b752ea0c28e3f7f0aaaad6abf84f735eebc37a60 <
    a5fe19dd8b3ed5fad6e5e0f0c58c7245043ee4af
  - >-
    Linux >= b752ea0c28e3f7f0aaaad6abf84f735eebc37a60 <
    c55599c0ec2aa020e41a0599c3044c56d8a2e7d9
  - >-
    Linux >= b752ea0c28e3f7f0aaaad6abf84f735eebc37a60 <
    a56c03a397e2cd0c4cf8da96dcd6214f7d0e7d8c
  - Linux a9165207b2b07415eeb01b3ac8bb84976ec96984
  - Linux >= 6.3.7 < 6.4
  - Linux 6.4
published: '2026-09-25'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T11:17:23.720'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-97960'
references:
  - url: 'https://git.kernel.org/stable/c/a56c03a397e2cd0c4cf8da96dcd6214f7d0e7d8c'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/a5fe19dd8b3ed5fad6e5e0f0c58c7245043ee4af'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/c55599c0ec2aa020e41a0599c3044c56d8a2e7d9'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-25T11:06:38.875Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

perf/x86/intel: Prevent drain_pebs() reentry

The PEBS buffer is shared by all events on a CPU, so drain_pebs() must
not be reentered. If so, one instance may observe stale buffer state and
potentially access out-of-bound memory.

Most invocations happen in NMI context, which naturally prevents reentry.
However, drain_pebs() is also reachable from process context via
intel_pmu_drain_pebs_buffer().

In those paths, the PMU is often already disabled, but not guaranteed.
For example, __intel_pmu_pebs_disable() only disables the target counter,
so other active counters can still raise a PMI and interrupt an in-flight
drain_pebs(). Here is an example,

__perf_addr_filters_adjust()
  perf_event_stop()
    __perf_event_stop()
      x86_pmu_stop() (event->pmu->stop)
        intel_pmu_disable_event()
          intel_pmu_pebs_disable()
            __intel_pmu_pebs_disable()
              intel_pmu_drain_large_pebs()
                intel_pmu_drain_pebs_buffer()

Introduce __intel_pmu_quiesce() and __intel_pmu_resume() helpers and
use them in intel_pmu_drain_large_pebs() to disable the full PMU
around the intel_pmu_drain_pebs_buffer() call, preventing reentry.

Also add a warning in intel_pmu_drain_pebs_buffer() when the full PMU is
not disabled.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
