Impact
The Linux kernel’s Intel PMU LBR (Last Branch Record) filtering logic was incomplete. A user‑only branch sampling request could still return LBR entries that contain kernel addresses because the from address was not validated against the requested privilege filter. This flaw allows a local user to extract kernel memory addresses through the perf utility.
Affected Systems
Any Linux kernel that has not yet incorporated the commit extending intel_pmu_lbr_filter to validate both from and to addresses is affected. The advisory does not list specific releases, so all kernels lacking this patch are potentially vulnerable.
Risk and Exploitability
The EPSS score is less than 1%, indicating a low probability of observed exploitation. The vulnerability is not cataloged in the CISA KEV database. Attack requires a local user with permission to run perf and enable branch filtering options; thus the likely attack vector is a local user utilizing 'perf record' with branch sampling. Because the exposure is limited to kernel address disclosure and not direct code execution or denial of service, the risk is moderate.
OpenCVE Enrichment
Debian DLA
Debian DSA