Bug 2540403 (CVE-2026-97499) - CVE-2026-97499 kernel: coresight: perf: Retrieve path and source from event data
Summary: CVE-2026-97499 kernel: coresight: perf: Retrieve path and source from event data
Keywords:
Status: NEW
Alias: CVE-2026-97499
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-24 16:42 UTC by OSIDB Bzimport
Modified: 2026-09-30 09:01 UTC (History)
17 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-09-24 16:42:26 UTC
In the Linux kernel, the following vulnerability has been resolved:

coresight: perf: Retrieve path and source from event data

ETM perf callbacks currently use the per-CPU csdev_src pointer, which
can race with updates during device registration and unregistration.

The AUX setup already builds and stores the path in the event data.
Use this path to retrieve the source instead of csdev_src to avoid
the race.

Export coresight_get_source() and add etm_event_get_ctxt_path() to
retrieve the context's path and its source with READ_ONCE() /
WRITE_ONCE() accessors. Give the comments to explain why this
approach is safe when pause or resume callbacks preempt the disable
callback (e.g. via NMI).


Note You need to log in before you can comment on or make changes to this bug.