CVE-2026-23271
In the Linux kernel, the following vulnerability has been resolved: perf: Fix __perf_event_overflow() vs perf_remove_from_context() race Make sure that __perf_event_overflow() runs with IRQs disabled for all possible callchains. Specifically the software events can end up running it with only preemption disabled. This opens up a race vs perf_event_exit_event() and friends that will go and free various things the overflow path expects to be present, like the BPF program.
- Affected products
- Linux Kernel
- Linux Linux Kernel
- < 6.1.167, 6.6.130, 6.12.77, 6.18.17, 6.19.7, 7.0
- CVSS 3.1
- 7.8 HIGH
- EPSS
- 0.1% (1th percentile)
- Weakness
- CWE-362
- NVD status
- Modified
- Published
- 2026-03-20
CVE-2026-23271 at NVD
1 known exploit for CVE-2026-23271
Proof-of-concept code and exploit modules indexed by Sploitus