← All Advisories

CVE-2026-97587

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-97587

Key Details

CVECVE-2026-97587
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

perf: RISC-V: store available counter mask as bitmap

The available-counter mask was a single unsigned long, but iteration

uses RISCV_MAX_COUNTERS, which is 64. On RV32 that reads past the object.

Filling with an unsigned-long bit at index 32 and above is also wrong.

Use DECLARE_BITMAP and set_bit/bitmap helpers. Walk each bitmap word

into CFG_MATCH when checking events, when allocating an index, and when

stopping all counters. Set the counter base to i times BITS_PER_LONG.

Share the CFG_MATCH ecall through a small helper so the 32-bit argument

split is not duplicated. On qemu-system-riscv32 the probe bitmap has bits

above XLEN set, so the first word alone is not enough.

[[email protected]: updated to apply; fixed checkpatch.pl issues] (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-97587
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-97587