CVE-2026-64402: coresight: ultrasoc-smb: Fix OOB write in smb_sync_perf_buffer()
In the Linux kernel, the following vulnerability has been resolved:
coresight: ultrasoc-smb: Fix OOB write in smbsyncperfbuffer()
When the SMB sink is used as a perf AUX sink, smbupdatebuffer() calls smbsyncperfbuffer() to copy hardware trace data into the perf AUX ring buffer pages. It derives pgidx = head >> PAGESHIFT from @head, which is handle->head, and indexes dstpages[pgidx]. The pgidx %= nrpages normalization is only applied after the first loop iteration.
This leaves the initial page index underived from the buffer size, which can result in an out-of-bounds write past dstpages[] when head exceeds the AUX buffer size.
Normalize head modulo the AUX buffer size before deriving the page index and offset, mirroring tmcetrsyncperfbuffer().