Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
A vulnerability in the Linux kernel's performance metrics handling has been identified, specifically affecting Raptor Lake machines. This issue, which leads to a hard-lockup crash, was discovered by the perf fuzzer. The crash occurs on E-core CPUs that do not support the performance metrics feature. The problem arises in the 'icl_update_topdown_event()' function, which incorrectly invokes topdown performance metrics on these unsupported CPUs. This vulnerability is a regression introduced by a previous commit that altered how topdown events are managed, leading to improper checks and the subsequent crash.
Exploitation of this vulnerability causes a hard-lockup crash, disrupting system operations and potentially leading to a denial of service.
Users can upgrade to the latest version of the Linux kernel where this vulnerability has been addressed. Consult the Linux kernel changelog or your distribution's update guidelines for specific instructions.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.