Executive brief
The Linux kernel's performance monitoring subsystem could incorrectly enable Branch Record Sampling (BRS) when virtualization (KVM/SVM) is toggled on AMD processors. This causes a general protection fault when attempting to write to a deprecated hardware register, leading to kernel crashes and system instability during VM operations.
Technical details
The vulnerability exists in the perf/x86/amd/core subsystem where amd_pmu_enable_all() calls amd_brs_enable_all() during SVM virtualization state transitions. BRS and LBR are mutually exclusive hardware features tracked via cpuc->lbr_users. On PerfMonV2-capable processors without BRS support, the kernel incorrectly attempts to set the BRS enable bit in DebugExtnCfg (MSR 0xc000010f), which is deprecated on such hardware. This causes a #GP exception when cpuc->lbr_users > 0, even if only LBR events are active. The fix prevents BRS from being enabled during the event selector reprogramming path from amd_pmu_disable_virt().
Affected products
- Linux Linux kernel <UNKNOWN>
Timeline
- 2026-08-15: disclosed