Out-of-bounds read in Linux kernel - CVE-2026-80670
Published: August 28, 2026
Vulnerability details
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in machine__resolve() when parsing a crafted perf.data sample with a large CPU index. A local user can supply a specially crafted perf.data file to disclose sensitive information.
User interaction is required to open or process the crafted perf.data file.