{"id":"AZL-104247","summary":"CVE-2026-97961 affecting package kernel 6.6.157.1-1","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nperf/core: Allow list_del during perf_event_overflow()\n\nA PMU might use perf_sched_cb_inc() and perf_sched_cb_dec()\ninterface to get the PMU call back function pmu::sched_task\ninvoked at schedule in and schedule out. This is achieved\nby walking along the list anchored by sched_cb_list.\n\nThe following scenario might lead to a list corruption.\n\n   perf_pmu_sched_task()\n      for_each_list_entry(..., &sched_cb_list)\n      +--\u003e __perf_pmu_sched_task()\n           +--\u003e event-\u003epmu-\u003esched_task())\n                +--\u003e PMU_push_sample()\n                     +--\u003e perf_event_overflow()\n                          +--\u003e __perf_event_overflow()\n                               +--\u003e pmu-\u003estop()\n                                    +--\u003e perf_sched_cb_dec()\n                                         remove entry from sched_cb_list\n                                         while list node in use.\n\nThis happens when ioctl(fd, PERF_EVENT_IOC_REFRESH, xxx) has been\ninvoked and perf_event::event_limit hits zero.\n\nPrevent the list corruption and convert for_each_list_entry()\nto for_each_list_entry_safe().","modified":"2026-09-28T05:39:54Z","published":"2026-09-25T11:17:23Z","upstream":["CVE-2026-97961"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-97961"}],"affected":[{"package":{"name":"kernel","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/kernel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.6.157.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-104247.json"}}],"schema_version":"1.9.0"}