HarborGuard / CVE
Back to search
HIGHCVE-2026-23271Published Modified CNA Linux

CVE-2026-23271: perf: Fix __perf_event_overflow() vs perf_remove_from_context() race

In the Linux kernel, the following vulnerability has been resolved: perf: Fix __perf_event_overflow() vs perf_remove_from_context() race Make sure that __perf_event_overflow() runs with IRQs disabled for all possible callchains. Specifically the software events can end up running it with only preemption disabled. This opens up a race vs perf_event_exit_event() and friends that will go and free various things the overflow path expects to be present, like the BPF program.

Metrics

CVSS v3.1
7.8
Severity
HIGH
Fixed in
0
Affected Products
2

Fix available

03f89b61dd504c5b6711de9759e053b082f9abf124df1a45819e50993cb351682a6ae8e7ed2d233a04f8d5812337871227bb2c98669a87c306a2f86ef5c48fdc4b4623533d86e279f51531a7ba212eb876.1.1676.6.1306.12.776.18.176.19.77.0bb190628fe5f2a73ba762a9972ba16c5e895f73ec9bc1753b3cc41d0e01fbca7f035258b5f4db0ae
Affected packages
  • Linux / Linux
    < 4df1a45819e50993cb351682a6ae8e7ed2d233a0 (from 592903cdcbf606a838056bae6d03fc557806c914) · < 4f8d5812337871227bb2c98669a87c306a2f86ef (from 592903cdcbf606a838056bae6d03fc557806c914) · < 5c48fdc4b4623533d86e279f51531a7ba212eb87 (from 592903cdcbf606a838056bae6d03fc557806c914) · < 3f89b61dd504c5b6711de9759e053b082f9abf12 (from 592903cdcbf606a838056bae6d03fc557806c914) · < bb190628fe5f2a73ba762a9972ba16c5e895f73e (from 592903cdcbf606a838056bae6d03fc557806c914) · < c9bc1753b3cc41d0e01fbca7f035258b5f4db0ae (from 592903cdcbf606a838056bae6d03fc557806c914)
  • Linux / Linux
    2.6.31
    Fixed in 0, 6.1.167, 6.6.130, 6.12.77, 6.18.17, 6.19.7, 7.0
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H