GPU VulnDB

Database/Kernel, userspace & hypervisor

Linux kernel perf: NULL pmu dereference when a PMU module unloads with an event open

UnscoredCVE-2026-98268Kernel, userspace & hypervisorcurated

Impact

perf_pmu_unregister() clears event->pmu while a perf event is still open; closing that event then reaches mediated_pmu_unaccount_event() through _free_event() and dereferences the NULL pmu pointer, producing a kernel oops. On a GPU node the PMU modules that get loaded and unloaded include uncore and vendor performance drivers, and the crash takes the whole host down with every tenant workload on it. Exploitation requires the ability to unload a PMU module, so the realistic exposure is an operator or automation race during driver updates rather than a tenant attack, plus incorrect nr_include_guest_events accounting on the KVM mediated-PMU path.

Who can reach it

Local privileged action - loading/unloading a PMU module (root or equivalent) while an unprivileged perf event is open. Not reachable by a tenant that cannot unload modules.

What to do

Apply the stable fix that NULL-checks the pmu in is_include_guest_event() and unaccounts before clearing event->pmu. Kernel update plus a reboot of each node, so schedule with a drain. Operationally, avoid unloading PMU modules while perf consumers are attached. No CVSS score or vendor advisory in the record.

References

Related entries

All Kernel, userspace & hypervisor entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.