Description
In the Linux kernel, the following vulnerability has been resolved:

coresight: etm4x: fix underflow for usage of (nrseqstate - 1)

According to IHI006H Embedded Trace Macrocell Architecture
Specification[0], TRCSEQEVR<n> is implemented only when
TRCIDR5.NUMSEQSTATE is 0b100, in which case n ranges from 0 to 2;
otherwise, TRCIDR5.NUMSEQSTATE is 0b000.

IOW, the number of usage in the initialisation or setting
TRCSEQEVR<n> with drvdata->nrseqstate - 1 in the loop could make
underflow issue when TRCIDR5.NUMSEQSTATE is 0b000.

Therefore, introduce nr_seq_ctrls field and untie it from nrseqstate.
As part of this introduce ETM_MAX_SEQ_TRANSITIONS macro and
apply nr_seq_ctrls and above macro to TRCSEQEVR<n> relevant fields setup.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Kernel Memory Corruption
Action: Apply Patch
AI Analysis

Impact

The Linux kernel’s coresight ETM (Embedded Trace Macrocell) driver contains a loop that calculates an index using the expression (nrseqstate - 1). When the hardware register TRCIDR5.NUMSEQSTATE is 0b000, this calculation underflows, producing a large unsigned value that can index outside the intended array bounds. The resulting out‑of‑bounds write can corrupt kernel memory, potentially allowing an attacker with sufficient local privileges to gain elevated privileges or cause a denial of service. The weakness is a classic integer underflow that leads to an unsafe use of an array index. The likely attack vector is inferred to be a local attacker with the ability to execute code with kernel privileges, such as via a malicious module.

Affected Systems

All Linux kernel releases that contain the unpatched coresight ETM driver are affected. The vulnerability exists in every vendor’s Linux kernel that has not incorporated the commit 1674d9bff8073bdee5dbc200f56fc3caa28d0566 or later.

Risk and Exploitability

The EPSS score is below 1%, and the vulnerability is not listed in CISA’s KEV catalog, indicating a low probability of exploitation in the wild. Nevertheless, because the flaw occurs in kernel space, a local attacker who can execute code with kernel privileges—such as by loading a malicious module—could potentially exploit the integer underflow. The likely attack vector is inferred to be local privileged code execution, as the vulnerability is within kernel space and requires code that can write kernel memory. Theoretical impact is high (kernel memory corruption), but current exploit likelihood remains low.

Generated by OpenCVE AI on September 20, 2026 at 02:01 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that includes the fix commit 1674d9bff8073bdee5dbc200f56fc3caa28d0566 or later.
  • If an immediate kernel update is not available, recompile the kernel with the CONFIG_ETM driver disabled in the configuration to eliminate the vulnerable code path.
  • Enable kernel hardening features such as signed module enforcement, SELinux/AppArmor, or the Linux Lockdown LSM to restrict local code execution until the kernel can be updated or ETM disabled.

Generated by OpenCVE AI on September 20, 2026 at 02:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sun, 20 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-188
CWE-787

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: coresight: etm4x: fix underflow for usage of (nrseqstate - 1) According to IHI006H Embedded Trace Macrocell Architecture Specification[0], TRCSEQEVR<n> is implemented only when TRCIDR5.NUMSEQSTATE is 0b100, in which case n ranges from 0 to 2; otherwise, TRCIDR5.NUMSEQSTATE is 0b000. IOW, the number of usage in the initialisation or setting TRCSEQEVR<n> with drvdata->nrseqstate - 1 in the loop could make underflow issue when TRCIDR5.NUMSEQSTATE is 0b000. Therefore, introduce nr_seq_ctrls field and untie it from nrseqstate. As part of this introduce ETM_MAX_SEQ_TRANSITIONS macro and apply nr_seq_ctrls and above macro to TRCSEQEVR<n> relevant fields setup.
Title coresight: etm4x: fix underflow for usage of (nrseqstate - 1)
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:08:07.269Z

Reserved: 2026-09-11T19:38:34.797Z

Link: CVE-2026-90274

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:23.997

Modified: 2026-09-17T17:17:23.997

Link: CVE-2026-90274

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T02:15:17Z

Weaknesses