Description
In the Linux kernel, the following vulnerability has been resolved:

perf: arm_pmuv3: Zero initialize hw_id branch stack field

PERF_SAMPLE_BRANCH_HW_INDEX is supported by BRBE so hw_id is passed to
userspace, but it's never set by the BRBE driver. Zero initialize it as
it should be according to the docs:

* For the architectures whose raw branch records are
* already stored in age order, the hw_idx should be 0.

It's probably too risky to remove PERF_SAMPLE_BRANCH_HW_INDEX from BRBE
now in case anyone is setting it and reading the value, but zero
initializing the whole struct also protects against the same issue with
new fields that are added in the future.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure via Uninitialized Perf Sample Field
Action: Patch
AI Analysis

Impact

The flaw in the arm_pmuv3 perf driver allowed a hardware identifier field to be passed to userspace without being initialized. Based on the description, it is inferred that a userspace process that reads perf sample data could receive residual kernel memory. Because the field could contain garbage or sensitive data, an attacker could gather unintended information. The patch zero‑initializes the field, which also protects future extensions. This vulnerability is a data disclosure issue rather than an execution or denial of service flaw, so it does not directly compromise system control.

Affected Systems

The vulnerability affects any Linux kernel build that includes the arm_pmuv3 branch‑record brute‑force (BRBE) component and that exposes PERF_SAMPLE_BRANCH_HW_INDEX to userspace. It is inferred that no specific distribution versions are listed, so any kernel version prior to the patch may be vulnerable. Systems without arm_pmuv3 support or that disable BRBE are not impacted.

Risk and Exploitability

The EPSS score of less than 1% indicates that exploitation is considered unlikely; the vulnerability is not listed in the CISA KEV catalog. It is inferred that an attacker would need to read perf sample data from a privileged or otherwise acceptable userspace context, meaning the attack surface is limited. Because the disallowed data is simply garbage, the impact is mostly limited to exposing unused memory contents rather than secret values or code execution. Consequently, the overall risk is low, though it merits remediation to avoid inadvertent information leaks.

Generated by OpenCVE AI on September 20, 2026 at 01:02 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the kernel update that includes the zero‑initialization fix for the arm_pmuv3 hw_id field.
  • Rebuild or reinstall any custom kernel modules that depend on the arm_pmuv3 perf interface.
  • Verify that the kernel is configured to use the updated perf driver and that no legacy configuration exposes PERF_SAMPLE_BRANCH_HW_INDEX to untrusted userspace.

Generated by OpenCVE AI on September 20, 2026 at 01:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 01:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-788

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: perf: arm_pmuv3: Zero initialize hw_id branch stack field PERF_SAMPLE_BRANCH_HW_INDEX is supported by BRBE so hw_id is passed to userspace, but it's never set by the BRBE driver. Zero initialize it as it should be according to the docs: * For the architectures whose raw branch records are * already stored in age order, the hw_idx should be 0. It's probably too risky to remove PERF_SAMPLE_BRANCH_HW_INDEX from BRBE now in case anyone is setting it and reading the value, but zero initializing the whole struct also protects against the same issue with new fields that are added in the future.
Title perf: arm_pmuv3: Zero initialize hw_id branch stack field
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:08:05.965Z

Reserved: 2026-09-11T19:38:34.797Z

Link: CVE-2026-90272

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:23.773

Modified: 2026-09-17T17:17:23.773

Link: CVE-2026-90272

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T01:15:07Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-788

    Access of Memory Location After End of Buffer