CVE-2026-23271

HIGH EPSS 0.9%
Published Mar 20, 20263mo ago · Modified May 22, 20261mo ago
7.8 CVSS 3.1
High
Find Similar
Published Mar 20, 2026 3mo ago
Last Modified May 22, 2026 1mo ago

Description

In the Linux kernel, the following vulnerability has been resolved: perf: Fix __perf_event_overflow() vs perf_remove_from_context() race Make sure that __perf_event_overflow() runs with IRQs disabled for all possible callchains. Specifically the software events can end up running it with only preemption disabled. This opens up a race vs perf_event_exit_event() and friends that will go and free various things the overflow path expects to be present, like the BPF program.

CVSS Details

Base Score
7.8
Exploitability
1.8
Impact
5.9
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector Local
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality High
Integrity High
Availability High

Threat Intelligence

EPSS Exploit Probability
0.9% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Weaknesses 1

CWE-362

Affected Products 6

VendorProductVersionRange
linuxlinux_kernel*≥2.6.31  –  <6.1.167
linuxlinux_kernel*≥6.2  –  <6.6.130
linuxlinux_kernel*≥6.7  –  <6.12.77
linuxlinux_kernel*≥6.13  –  <6.18.17
linuxlinux_kernel*≥6.19  –  <6.19.7
linuxlinux_kernel7.0any

References 6

  • git.kernel.org https://git.kernel.org/stable/c/3f89b61dd504c5b6711de9759e053b082f9abf12
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/4df1a45819e50993cb351682a6ae8e7ed2d233a0
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/4f8d5812337871227bb2c98669a87c306a2f86ef
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/5c48fdc4b4623533d86e279f51531a7ba212eb87
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/bb190628fe5f2a73ba762a9972ba16c5e895f73e
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/c9bc1753b3cc41d0e01fbca7f035258b5f4db0ae
    Patch

Remediation

  • git.kernel.org https://git.kernel.org/stable/c/3f89b61dd504c5b6711de9759e053b082f9abf12
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/4df1a45819e50993cb351682a6ae8e7ed2d233a0
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/4f8d5812337871227bb2c98669a87c306a2f86ef
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/5c48fdc4b4623533d86e279f51531a7ba212eb87
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/bb190628fe5f2a73ba762a9972ba16c5e895f73e
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/c9bc1753b3cc41d0e01fbca7f035258b5f4db0ae
    Patch