CVE-2026-23271: Linux Kernel

High severity, CVSS 7.8. EPSS: 0.1% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: perf: Fix __perf_event_overflow() vs perf_remove_from_context() race Make sure that __perf_event_overflow() runs with IRQs disabled for all possible callchains. Specifically the software events can end up running it with only preemption disabled. This opens up a race vs perf_event_exit_event() and friends that will go and free various things the overflow path expects to be present, like the BPF program.

Affected products

  • Linux Linux Kernel: from 2.6.31, before 6.1.167 (fixed in 6.1.167); from 6.2, before 6.6.130 (fixed in 6.6.130); from 6.7, before 6.12.77 (fixed in 6.12.77); from 6.13, before 6.18.17 (fixed in 6.18.17); from 6.19, before 6.19.7 (fixed in 6.19.7); version 7.0 only

Published 2026-03-20. Last modified 2026-07-14.