CVE-2026-98268: perf: Fix null pointer access in is_include_guest_event()
In the Linux kernel, the following vulnerability has been resolved:
perf: Fix null pointer access in isincludeguestevent()
A typical module unload occurring event when there is an active perf connection leads to freeing of the pmu pointer. The call log is something like: .. pmudetachevent pmudetachevent pmudetachevents perfpmuunregister ..
pmudetachevent() sets event->pmu to null. When the perf connection finally is closed, the following stack trace is observed:
Oops: general protection fault, kernel NULL pointer dereference ... RIP: 0010:freeevent+0x3e/0x370 ... Call Trace: ... perfeventreleasekernel+0x260/0x2d0 perfrelease+0x12/0x20
A call to mediatedpmuunaccountevent() inside freeevent() is the root cause of this crash. Adding a check inside isincludeguestevent() ensures we don't accidentally access a null pmu ptr. In addition to this, we will now call mediatedpmuunaccountevent() before clearing the pmu ptr so that nrincludeguestevents counts are maintained correctly.