Junglewise Threat Intelligence

CVE-2026-53370: Linux Kernel Intel PMU improper validation of ACR masks

CVE-2026-53370 · Severity: info · CVSS 0 · Published 2026-07-19

Technologies: Linux. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's performance monitoring subsystem for Intel processors. This component is responsible for tracking hardware performance metrics used by developers and system administrators to optimize software. The flaw could allow improper configuration of hardware performance counters, potentially leading to inaccurate system monitoring or unexpected behavior in performance-tracking tools.

Technical details

The vulnerability stems from incomplete validation of user-space ACR masks (attr.config2) in the Intel PMU driver. Specifically, the kernel failed to verify if mask indices belonged to the correct ACR event group, utilized an early return that caused subsequent ACR groups to be skipped upon encountering invalid bits, and failed to clear stale hardware masks (hw.config1) before applying new configurations. An attacker with local access to performance monitoring interfaces could potentially provide malformed masks to cause bit-shifting errors or incorrect hardware counter configurations. The issue was resolved by improving mask validation logic, ensuring iteration continues after encountering invalid bits, and explicitly clearing stale hardware masks.

Affected products

  • Linux Linux 6.16 to 6.18.30, 7.0 to 7.0.7

Timeline

  • 2026-07-19: disclosed
  • 2026-07-19: advisory

References