Executive brief
The Linux kernel's perf profiling tool improperly validates CPU indices when processing perf.data sample files. An attacker can craft a malicious perf.data file with an out-of-bounds CPU index to trigger a heap buffer read, potentially leaking sensitive kernel memory or causing a system crash. This affects any system using perf to analyze performance data.
Technical details
The vulnerability is an out-of-bounds heap read in the perf tools' machine__resolve() function (tools/perf/util/event.c). The code accesses env->cpu[al->cpu].socket_id after validating that al->cpu >= 0 and env->cpu is non-NULL, but fails to validate that al->cpu does not exceed env->nr_cpus_avail. Since al->cpu originates from untrusted perf.data sample data, a crafted file with a large CPU index causes an out-of-bounds heap read. Additionally, integer truncation when casting to struct perf_cpu (int16_t) allows values like 65536 to silently wrap to 0, bypassing bounds checks. The fix adds proper bounds validation via perf_env__get_cpu_topology() before accessing the heap structure. Patches are available in the stable Linux kernel tree.
Affected products
- Linux Linux kernel Various stable branches (4.x through 7.x series)
Timeline
- 2026-08-28: disclosed: CVE published
- 2026-06-06: patched: Fix committed to upstream Linux kernel
- 2026-07-24: patched: Fix backported to stable Linux branches