{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  perf/x86/intel: Prevent drain_pebs() reentry  The PEBS buffer is shared by all events on a CPU, so drain_pebs() must not be reentered. If so, one instance may observe stale buffer state and potentially access out-of-bound memory.  Most invocations happen in NMI context, which naturally prevents reentry. However, drain_pebs() is also reachable from process context via intel_pmu_drain_pebs_buffer().  In those paths, the PMU is often already disabled, but not guaranteed. For example, __intel_pmu_pebs_disable() only disables the target counter, so other active counters can still raise a PMI and interrupt an in-flight drain_pebs(). Here is an example,  __perf_addr_filters_adjust()   perf_event_stop()     __perf_event_stop()       x86_pmu_stop() (event-\u003epmu-\u003estop)         intel_pmu_disable_event()           intel_pmu_pebs_disable()             __intel_pmu_pebs_disable()               intel_pmu_drain_large_pebs()                 intel_pmu_drain_pebs_buffer()  Introduce __intel_pmu_quiesce() and __intel_pmu_resume() helpers and use them in intel_pmu_drain_large_pebs() to disable the full PMU around the intel_pmu_drain_pebs_buffer() call, preventing reentry.  Also add a warning in intel_pmu_drain_pebs_buffer() when the full PMU is not disabled.",
  "id": "DEBIAN-CVE-2026-97960",
  "modified": "2026-09-26T04:47:37.810733423Z",
  "published": "2026-09-25T11:17:23.720Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-97960"
    }
  ],
  "upstream": [
    "CVE-2026-97960"
  ]
}