Heap-based buffer overflow in Linux kernel - CVE-2026-80671
Published: August 28, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to heap-based buffer overflow in register_pid() in tools/perf/builtin-sched.c when processing an untrusted comm string from perf.data. A local user can supply a crafted perf.data file containing an oversized comm value to cause a denial of service.
The overflow occurs because the comm value is copied into a fixed 20-byte COMM_LEN buffer without a length check.