PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-43416 Linux CVE debrief

A NULL pointer dereference vulnerability exists in the Linux kernel's PowerPC performance monitoring subsystem. When collecting user-space callchains via perf, the kernel fails to verify that `current->mm` (the current process's memory descriptor) is still valid. If the process's memory context has already been released—such as during process exit while BPF profiling programs are still executing—subsequent access to `current->mm` triggers a kernel panic. The vulnerability manifests as a NULL pointer dereference at offset 0x588 (likely within `mm_struct` field access), causing an oops with SIGSEGV. This was reproducible using BCC's profile.py BPF tool. The fix adds a NULL check for `current->mm` before attempting to walk the user callchain, mirroring a prior x86 fix (commit 20afc60f892d), and relocates top-level stack entry capture to ensure it's preserved even when `current->mm` is NULL.

Vendor
Linux
Product
Unknown
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-08
Original CVE updated
2026-05-26
Advisory published
2026-05-08
Advisory updated
2026-05-26

Who should care

Linux kernel maintainers and system administrators running PowerPC-based systems with performance monitoring or BPF tracing enabled; security teams monitoring for kernel stability issues in production environments using eBPF/BCC tooling

Technical summary

The vulnerability occurs in `perf_callchain_user_64()` on PowerPC when walking user-space callchains. The function assumes `current->mm` is valid, but during process teardown or in certain BPF execution contexts, the memory descriptor may be NULL. Accessing `current->mm` without validation causes a NULL pointer dereference. The fix introduces an explicit NULL check before dereferencing `current->mm`, consistent with x86 architecture handling. Additionally, the top-level stack entry capture is moved to the generic `perf_callchain_user()` to ensure stack traces remain useful even when user-space walk is skipped due to NULL `mm`.

Defensive priority

medium

Recommended defensive actions

  • Apply the relevant stable kernel patch for your version series: 6.18.x, 6.19.x, or 7.0-rc
  • Upgrade to Linux kernel 6.18.19, 6.19.9, or 7.0-rc4 or later when available
  • If running BPF profiling tools on PowerPC systems, consider temporarily disabling user-space stack walking until patched
  • Monitor kernel logs for 'BUG: Kernel NULL pointer dereference' or 'perf_callchain_user' in stack traces as indicators of exploitation attempts

Evidence notes

The vulnerability description includes a kernel oops trace showing the crash path: `perf_callchain_user_64` → `perf_callchain_user` → `get_perf_callchain` → `bpf_get_stackid` → BPF program. The faulting instruction address and NULL dereference at 0x588 confirm the `mm_struct` access pattern. Three kernel.org stable patches are provided as fixes. CPE data indicates affected versions span Linux 2.6.32 through 6.18.18, 6.19 through 6.19.8, and 7.0-rc1 through rc3.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-43416 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-43416

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-43416 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-43416

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/7e5f60b8cfc02a2b23a40a5f5fd2fa81d010e737

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/98074e16742ae87fb82e234b419783c5ffc9baea

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/e9bbfb4bfa86c6b5515b868d6982ac60505d7e39

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.