Improper Check or Handling of Exceptional Conditions in Linux kernel - CVE-2026-80671

 

Improper Check or Handling of Exceptional Conditions in Linux kernel - CVE-2026-80671

Published: August 28, 2026


Vulnerability identifier: #VU146128
CSH Severity: Medium
CVSS v4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-80671
CWE-ID: CWE-703
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper exceptional condition handling in register_pid() in tools/perf/builtin-sched.c when reallocating sched->tasks while processing untrusted perf.data. A local user can supply crafted input that triggers realloc failure to cause a denial of service.

Direct reassignment of the realloc result can leak the original pointer and leave task state corrupted because the task count is updated before successful reallocation.


Affected software

Linux kernel

How to mitigate CVE-2026-80671

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3

External References

Related Security Bulletins