Operation on a Resource after Expiration or Release in Linux kernel - CVE-2026-97961

 

Operation on a Resource after Expiration or Release in Linux kernel - CVE-2026-97961

Published: September 28, 2026


Vulnerability identifier: #VU152518
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-97961
CWE-ID: CWE-672
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to corrupt the scheduler callback list.

The vulnerability exists due to unsafe list iteration in perf_pmu_sched_task() when processing perf PMU scheduler callbacks. A local user can invoke PERF_EVENT_IOC_REFRESH on a perf event to corrupt the scheduler callback list.

The issue is triggered when the event limit reaches zero during perf event overflow processing.


Affected software

Linux kernel

How to mitigate CVE-2026-97961

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3

External References

Related Security Bulletins