In the Linux kernel, the following vulnerability has been resolved:
coresight: ultrasoc-smb: Fix OOB write in smbsyncperf_buffer()
When the SMB sink is used as a perf AUX sink, smbupdatebuffer() calls smbsyncperfbuffer() to copy hardware trace data into the perf AUX ring buffer pages. It derives pgidx = head >> PAGESHIFT from @head, which is handle->head, and indexes dstpages[pgidx]. The pgidx %= nr_pages normalization is only applied after the first loop iteration.
This leaves the initial page index underived from the buffer size, which can result in an out-of-bounds write past dst_pages[] when head exceeds the AUX buffer size.
Normalize head modulo the AUX buffer size before deriving the page index and offset, mirroring tmcetrsyncperfbuffer().
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64402.json",
"cna_assigner": "Linux"
}