CVE-2026-31782

HIGH

perf/x86: Fix potential bad container_of in intel_pmu_hw_config

Title source: cna
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: perf/x86: Fix potential bad container_of in intel_pmu_hw_config Auto counter reload may have a group of events with software events present within it. The software event PMU isn't the x86_hybrid_pmu and a container_of operation in intel_pmu_set_acr_caused_constr (via the hybrid helper) could cause out of bound memory reads. Avoid this by guarding the call to intel_pmu_set_acr_caused_constr with an is_x86_event check.

Scores

CVSS v3 7.8
EPSS 0.0001
EPSS Percentile 2.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-125
Status published
Products (11)
Linux/Linux < 6.16
Linux/Linux 6.16
Linux/Linux 6.18.22 - 6.18.*
Linux/Linux 6.19.12 - 6.19.*
Linux/Linux 7.0
Linux/Linux ec980e4facef8110f6fce27e5b6344660117f01f - bfee04838f636d064bc92075c65c95f739003804
Linux/Linux ec980e4facef8110f6fce27e5b6344660117f01f - dbde07f06226438cd2cf1179745fa1bec5d8914a
Linux/Linux ec980e4facef8110f6fce27e5b6344660117f01f - e435a30ca6fe14c9611b1fc731c98a6d28410247
linux/linux_kernel 6.16
linux/linux_kernel 7.0 rc1 (6 CPE variants)
... and 1 more
Published May 01, 2026
Tracked Since May 01, 2026