CVE-2026-97960
In the Linux kernel, the following vulnerability has been resolved: perf/x86/intel: Prevent drain_pebs() reentry The PEBS buffer is shared by all events on a CPU, so drain_pebs() must not be reentered. If so, one instance may observe stale buffer state and potentially access out-of-bound memory. Most invocations happen in NMI context, which naturally prevents reentry. However, drain_pebs() is also reachable from process context via intel_pmu_drain_pebs_buffer(). In those paths, the PMU is often already disabled, but not guaranteed. For example, __intel_pmu_pebs_disable() only disables the target counter, so other active counters can still raise a PMI and interrupt an in-flight drain_pebs(). Here is an example, __perf_addr_filters_adjust() perf_event_stop() __perf_event_stop() x86_pmu_stop() (event->pmu->stop) intel_pmu_disable_event() intel_pmu_pebs_disable() __intel_pmu_pebs_disable() intel_pmu_drain_large_pebs() intel_pmu_drain_pebs_buffer() Introduce __intel_pmu_quiesce() and __intel_pmu_resume() helpers and use them in intel_pmu_drain_large_pebs() to disable the full PMU around the intel_pmu_drain_pebs_buffer() call, preventing reentry. Also add a warning in intel_pmu_drain_pebs_buffer() when the full PMU is not disabled.
Affected versions
Linux kernel versions
6.3.7,
6.4
and later are affected. Fixed in
6.18.53,
7.2.7,
7.3-rc3
and their respective stable series.
References
3 totalFrequently asked questions
-
What is CVE-2026-97960?
CVE-2026-97960 is a unscored severity Linux kernel vulnerability . It affects Linux kernel versions from 6.3.7 onward and has been patched in 6.18.53, 7.2.7 and 7.3-rc3. CVE-2026-97960 has not been confirmed as actively exploited and is not listed in the CISA KEV catalog.
-
Is there a patch available for CVE-2026-97960?
Yes. CVE-2026-97960 has been patched. Fixed versions include 6.18.53, 7.2.7 and 7.3-rc3. If you are running Linux kernel 6.3.7 or later up to the fix versions, apply the relevant patch for your kernel branch.
-
Is CVE-2026-97960 actively exploited?
No. CVE-2026-97960 has not been confirmed as actively exploited. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.