Impact
The Linux kernel CoreSight ETM4x driver contains a defect in the perf enable path where a function that disables an active configuration, cscfg_csdev_disable_active_config(), is omitted in certain error conditions. This omission can cause the internal field config_desc->active_cnt to remain exposed, allowing an attacker to read leaked configuration data and potentially infer system state or sensitive driver information. The weakness does not directly provide code execution but creates a credible information disclosure vector that could aid further exploitation.
Affected Systems
The affected product is the Linux kernel implemented across all distributions that ship the CoreSight ETM4x driver. No specific kernel version ranges are listed in the CNA data, so any kernel containing the susceptible ETM4x component may be vulnerable.
Risk and Exploitability
The EPSS score indicates a probability of exploitation lower than 1%, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited current exploitation activity. However, the potential for information disclosure, combined with the lack of compensating controls in the kernel, raises concern for environments where sensitive configurations are monitored. Attackers would need local kernel access or a prior foothold to trigger the perf enable path and recover the leaked counter. The overall risk remains moderate due to the low exploitation likelihood and the need for kernel permission.
OpenCVE Enrichment