LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-23271

linux · linux kernel

Published
CVSS7.8
Severityhigh
WeaknessCWE-362
ExploitedNot in CISA KEV

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Description

In the Linux kernel, the following vulnerability has been resolved: perf: Fix __perf_event_overflow() vs perf_remove_from_context() race Make sure that __perf_event_overflow() runs with IRQs disabled for all possible callchains. Specifically the software events can end up running it with only preemption disabled. This opens up a race vs perf_event_exit_event() and friends that will go and free various things the overflow path expects to be present, like the BPF program.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-23271

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-23271.