KernelScan.io

HIGH Public exploit Introduced in 2.6.31

perf Event Overflow Race

CVE-2026-23271

CVSS 7.8 / 10.0 NVD

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

KernelScan AI7.0HIGH

01

In the Linux kernel, the following vulnerability has been resolved: perf: Fix __perf_event_overflow() vs perf_remove_from_context() race Make sure that __perf_event_overflow() runs with IRQs disabled for all possible callchains. Specifically the software events can end up running it with only preemption disabled. This opens up a race vs perf_event_exit_event() and friends that will go and free various things the overflow path expects to be present, like the BPF program.

02

Engine v0.2.0

Risk summary

A race condition in the perf subsystem allows local attackers with low privileges to cause use-after-free conditions when perf events overflow while being removed from context. This can lead to kernel memory corruption, privilege escalation, or system crashes when BPF programs or other event resources are freed during overflow handling.

Affectedkernel/events/core.c (perf subsystem)

Vulnerability analysis

The vulnerability stems from insufficient synchronization in __perf_event_overflow() which can run with only preemption disabled for software events, creating a race window with perf_event_exit_event() that frees event resources like BPF programs. The fix ensures __perf_event_overflow() always runs with IRQs disabled and adds proper state checks with IRQ protection in the software event path (perf_swevent_event) to serialize against concurrent event removal. The attack surface is local-only, requiring perf_event_open() syscall access which typically needs CAP_PERFMON or relaxed perf_event_paranoid settings.

Exploit availability

KernelScan found public exploit code for this CVE. Open it in the CVE browser to see what we found, where, and how strong the evidence is — that needs a free account with a confirmed email address.

03

BranchIntroducedFixed inPatch commit
6.12.6.316.1.1674df1a45819e5
6.62.6.316.6.1304f8d58123378
6.122.6.316.12.775c48fdc4b462
6.182.6.316.18.173f89b61dd504
6.192.6.316.19.7bb190628fe5f
mainline2.6.317.0c9bc1753b3cc