Description
In the Linux kernel, the following vulnerability has been resolved:

coresight: etm4x: missing cscfg_csdev_disable_active_config() in perf enable

In the perf enable path, there are missing cases where
cscfg_csdev_disable_active_config() is not called:

- Branch broadcast is selected but not supported by the hardware
- etm4_enable_hw() fails

This can lead to a leak of config_desc->active_cnt.
Fix this by properly calling cscfg_csdev_disable_active_config()
in these error paths.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Apply Patch
AI Analysis

Impact

The Linux kernel CoreSight ETM4x driver contains a defect in the perf enable path where a function that disables an active configuration, cscfg_csdev_disable_active_config(), is omitted in certain error conditions. This omission can cause the internal field config_desc->active_cnt to remain exposed, allowing an attacker to read leaked configuration data and potentially infer system state or sensitive driver information. The weakness does not directly provide code execution but creates a credible information disclosure vector that could aid further exploitation.

Affected Systems

The affected product is the Linux kernel implemented across all distributions that ship the CoreSight ETM4x driver. No specific kernel version ranges are listed in the CNA data, so any kernel containing the susceptible ETM4x component may be vulnerable.

Risk and Exploitability

The EPSS score indicates a probability of exploitation lower than 1%, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited current exploitation activity. However, the potential for information disclosure, combined with the lack of compensating controls in the kernel, raises concern for environments where sensitive configurations are monitored. Attackers would need local kernel access or a prior foothold to trigger the perf enable path and recover the leaked counter. The overall risk remains moderate due to the low exploitation likelihood and the need for kernel permission.

Generated by OpenCVE AI on September 19, 2026 at 14:47 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Linux kernel update that includes the fix for the CoreSight etm4x perf enable path
  • Configure the kernel to restrict perf subsystem access to privileged users only
  • If an update is unavailable, disable perf features that invoke etm4x or lock down access to the CoreSight interfaces to prevent the leak

Generated by OpenCVE AI on September 19, 2026 at 14:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 15:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-665

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: coresight: etm4x: missing cscfg_csdev_disable_active_config() in perf enable In the perf enable path, there are missing cases where cscfg_csdev_disable_active_config() is not called: - Branch broadcast is selected but not supported by the hardware - etm4_enable_hw() fails This can lead to a leak of config_desc->active_cnt. Fix this by properly calling cscfg_csdev_disable_active_config() in these error paths.
Title coresight: etm4x: missing cscfg_csdev_disable_active_config() in perf enable
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:08:06.638Z

Reserved: 2026-09-11T19:38:34.797Z

Link: CVE-2026-90273

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:23.883

Modified: 2026-09-17T17:17:23.883

Link: CVE-2026-90273

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T15:00:12Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-665

    Improper Initialization