HIGH Public exploit Introduced in 2.6.31
perf Event Overflow Race
CVE-2026-23271
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
KernelScan AI7.0HIGH
01Description
In the Linux kernel, the following vulnerability has been resolved: perf: Fix __perf_event_overflow() vs perf_remove_from_context() race Make sure that __perf_event_overflow() runs with IRQs disabled for all possible callchains. Specifically the software events can end up running it with only preemption disabled. This opens up a race vs perf_event_exit_event() and friends that will go and free various things the overflow path expects to be present, like the BPF program.
02KernelScan AI Analysis
Risk summary
A race condition in the perf subsystem allows local attackers with low privileges to cause use-after-free conditions when perf events overflow while being removed from context. This can lead to kernel memory corruption, privilege escalation, or system crashes when BPF programs or other event resources are freed during overflow handling.
Vulnerability analysis
The vulnerability stems from insufficient synchronization in __perf_event_overflow() which can run with only preemption disabled for software events, creating a race window with perf_event_exit_event() that frees event resources like BPF programs. The fix ensures __perf_event_overflow() always runs with IRQs disabled and adds proper state checks with IRQ protection in the software event path (perf_swevent_event) to serialize against concurrent event removal. The attack surface is local-only, requiring perf_event_open() syscall access which typically needs CAP_PERFMON or relaxed perf_event_paranoid settings.
Exploit availability
KernelScan found public exploit code for this CVE. Open it in the CVE browser to see what we found, where, and how strong the evidence is — that needs a free account with a confirmed email address.
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| 6.1 | 2.6.31 | 6.1.167 | 4df1a45819e5 |
| 6.6 | 2.6.31 | 6.6.130 | 4f8d58123378 |
| 6.12 | 2.6.31 | 6.12.77 | 5c48fdc4b462 |
| 6.18 | 2.6.31 | 6.18.17 | 3f89b61dd504 |
| 6.19 | 2.6.31 | 6.19.7 | bb190628fe5f |
| mainline | 2.6.31 | 7.0 | c9bc1753b3cc |