Executive brief
The Linux kernel's performance monitoring subsystem contains a use-after-free vulnerability in the perf event group detachment logic. When CPU hotplug or other operations detach a sibling event from a group, the sibling retains a dangling pointer to the freed group leader. A user can trigger this by issuing ioctls on the detached event, causing a crash or potential code execution, affecting system stability and security on multi-core systems.
Technical details
The vulnerability exists in perf_group_detach() which handles detachment of performance events from groups differently depending on whether the leader or a sibling is removed. When a sibling is detached via DETACH_GROUP during CPU hotplug, its group_leader pointer is left pointing to the old leader even after the sibling is removed from the group's sibling_list. If the leader is subsequently freed and closed, a PERF_IOC_FLAG_GROUP ioctl call on the detached sibling will dereference a freed pointer, triggering a kernel panic. The attack vector is local (requires file descriptor) and unprivileged user can trigger it, though it requires specific timing with CPU hotplug events. The fix promotes detached siblings to singleton events and updates their group_leader pointer to themselves.
Affected products
- Linux Linux kernel 6.18.7 and likely earlier versions
Timeline
- 2026-08-22: disclosed
- other: Fix available in kernel commit resolving perf_group_detach() to promote detached siblings to singleton events