SB20260828103 - Improper Check or Handling of Exceptional Conditions in Linux kernel perf



SB20260828103 - Improper Check or Handling of Exceptional Conditions in Linux kernel perf

Published: August 28, 2026

Security Bulletin ID SB20260828103
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Denial of service

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Improper Check or Handling of Exceptional Conditions (CVE-ID: CVE-2026-80671)

CWE-ID: CWE-703 - Improper Check or Handling of Exceptional Conditions

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper exceptional condition handling in register_pid() in tools/perf/builtin-sched.c when reallocating sched->tasks while processing untrusted perf.data. A local user can supply crafted input that triggers realloc failure to cause a denial of service.

Direct reassignment of the realloc result can leak the original pointer and leave task state corrupted because the task count is updated before successful reallocation.


Remediation

Install update from vendor's website.