Race condition in Linux kernel - CVE-2026-97499
Published: September 24, 2026
Vulnerability details
The vulnerability allows a local user to trigger a race condition.
The vulnerability exists due to a race condition in the CoreSight ETM perf callbacks when device registration or unregistration updates the per-CPU source device pointer. A local user can invoke perf event callbacks concurrently with these updates to trigger a race condition.
AUX pause or resume callbacks may preempt the disable callback in NMI context.