Database/Kernel, userspace & hypervisor
Linux kernel perf: NULL pmu dereference when a PMU module unloads with an event open
Impact
perf_pmu_unregister() clears event->pmu while a perf event is still open; closing that event then reaches mediated_pmu_unaccount_event() through _free_event() and dereferences the NULL pmu pointer, producing a kernel oops. On a GPU node the PMU modules that get loaded and unloaded include uncore and vendor performance drivers, and the crash takes the whole host down with every tenant workload on it. Exploitation requires the ability to unload a PMU module, so the realistic exposure is an operator or automation race during driver updates rather than a tenant attack, plus incorrect nr_include_guest_events accounting on the KVM mediated-PMU path.
Who can reach it
Local privileged action - loading/unloading a PMU module (root or equivalent) while an unprivileged perf event is open. Not reachable by a tenant that cannot unload modules.
What to do
Apply the stable fix that NULL-checks the pmu in is_include_guest_event() and unaccounts before clearing event->pmu. Kernel update plus a reboot of each node, so schedule with a drain. Operationally, avoid unloading PMU modules while perf consumers are attached. No CVSS score or vendor advisory in the record.
References
Related entries
- Linux kernel x86/kprobes: wrong return address when probing a CS-prefixed CALL crashes the hostCVE-2026-98273 · Linux kernel x86/kprobes (int3_emulate_call instruction length)Unscored
- powerpc/iommu: TCE IOBA range check ignores npages, allowing out-of-range table accessCVE-2026-98282 · Linux kernel powerpc/iommu (iommu_tce_check_ioba npages validation)Unscored
- KVM PPC Book3S HV: use-after-free on nested guest struct during all-LPID tlbie emulationCVE-2026-98283 · Linux kernel KVM PPC Book3S HV (kvmhv_emulate_tlbie_all_lpid)Unscored
- Microsoft Hyper-V: vmswitch fails to validate guest OID requestsCVE-2021-28476 · Microsoft Hyper-VCritical
- Incus: instance snapshots bypass restricted.containers.lowlevel, giving command execution on the hostCVE-2026-48751 · Incus (instance snapshots ignore restricted.containers.lowlevel)Critical
- VMware ESXi (OpenSLP): Use-after-free in OpenSLP on port 427 - unauthenticated remote code execution on the hypervisorCVE-2020-3992 · VMware ESXi (OpenSLP)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.