Executive brief
A vulnerability in the Linux kernel's hardware tracing component could allow an attacker to cause a system crash or potentially corrupt memory. The issue occurs when the system handles hardware trace data, specifically within the UltraSoc System Memory Buffer driver. This could impact the stability and reliability of servers or devices using this specific hardware tracing feature.
Technical details
An out-of-bounds (OOB) write vulnerability exists in 'drivers/hwtracing/coresight/ultrasoc-smb.c' within the 'smb_sync_perf_buffer()' function. The root cause is a failure to normalize the initial page index ('pg_idx') against the buffer size ('nr_pages') before indexing the 'dst_pages' array. When the 'head' pointer exceeds the AUX buffer size, the kernel may write data past the intended buffer boundaries. This issue is triggered when the SMB sink is utilized as a perf AUX sink to copy hardware trace data. Patches have been released across multiple stable kernel branches to normalize the 'head' modulo the AUX buffer size.
Affected products
- Linux Linux 6.3 to 6.6.145, 6.12.96, 6.18.39, 7.1.4
Timeline
- 2026-07-25: disclosed: CVE published by kernel.org
- 2026-07-25: advisory
References
- https://git.kernel.org/stable/c/38dbc8db8341ccdf8e1e1a067453d33ad751864b
- https://git.kernel.org/stable/c/4c5a0a946373da99a80398289b28845b5ae40cd1
- https://git.kernel.org/stable/c/661a019ac0413ecec9e5d1dfcc12fbca8e78d5fb
- https://git.kernel.org/stable/c/98495b5a4d77dd22e106f462b76e1093a55b29a7
- https://git.kernel.org/stable/c/daf6246ab988fc8bdc82ad7c8d0b1c182d11b15f