PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-97499 Linux CVE debrief

A Linux kernel vulnerability was resolved, addressing a race condition in the CoreSight perf callbacks. The issue arises from the use of the per-CPU csdev_src pointer, which can be updated during device registration and unregistration. To mitigate this, the AUX setup builds and stores the path in the event data, and this path is used to retrieve the source instead of csdev_src.

Vendor
Linux
Product
Unknown
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-24
Original CVE updated
2026-09-28
Advisory published
2026-09-24
Advisory updated
2026-09-28

Who should care

Linux kernel maintainers, users, and administrators should assess exposure and verify the presence of the fix in their systems. They should review Linux kernel versions, assess the presence of the fix, and monitor system logs for potential exploitation attempts. The vulnerability affects the Linux kernel, and its impact needs to be evaluated by the relevant stakeholders.

Why it matters

A Linux kernel vulnerability was resolved, addressing a race condition in the CoreSight perf callbacks. Linux kernel maintainers and users should assess exposure and verify the presence of the fix in their systems.

  • Verify Linux kernel versions for potential exposure
  • Assess the presence of the fix in the Linux kernel

Technical summary

The Linux kernel vulnerability, CVE-2026-97499, addresses a race condition in the CoreSight perf callbacks. The AUX setup builds and stores the path in the event data, which is used to retrieve the source instead of csdev_src. This change helps to avoid the race condition. The vulnerability affects the Linux kernel and requires verification of the presence of the fix in the system. The impact of the vulnerability and the affected versions need to be assessed by Linux kernel maintainers, users, and administrators. The vulnerability has been resolved, and the fix is available in the Linux kernel.

Defensive priority

Linux kernel maintainers and users should assess exposure and verify the presence of the fix in their systems.

Recommended defensive actions

  • Review Linux kernel versions and assess exposure to the vulnerability
  • Verify the presence of the fix in the Linux kernel
  • Monitor system logs for potential exploitation attempts
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, but the impact and affected versions require further verification. The Linux kernel vulnerability, CVE-2026-97499, addresses a race condition in the CoreSight perf callbacks. The AUX setup builds and stores the path in the event data, which is used to retrieve the source instead of csdev_src. This change helps to avoid the race condition. However, the specific versions of the Linux kernel that are affected and the severity of the vulnerability need to be verified.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-97499 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-97499

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-97499 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-97499

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/0f4cb08f30011b7625a4fba668fa5c36da5e6637

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/f37bc31447c0ddafedb25e3c4a4f4e2284034247

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.