Junglewise Threat Intelligence

CVE-2026-80670: Linux kernel perf tools out-of-bounds heap read in machine__resolve()

CVE-2026-80670 · Severity: critical · CVSS 9.1 · Published 2026-08-28

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's perf profiling tool improperly validates CPU indices when processing perf.data sample files. An attacker can craft a malicious perf.data file with an out-of-bounds CPU index to trigger a heap buffer read, potentially leaking sensitive kernel memory or causing a system crash. This affects any system using perf to analyze performance data.

Technical details

The vulnerability is an out-of-bounds heap read in the perf tools' machine__resolve() function (tools/perf/util/event.c). The code accesses env->cpu[al->cpu].socket_id after validating that al->cpu >= 0 and env->cpu is non-NULL, but fails to validate that al->cpu does not exceed env->nr_cpus_avail. Since al->cpu originates from untrusted perf.data sample data, a crafted file with a large CPU index causes an out-of-bounds heap read. Additionally, integer truncation when casting to struct perf_cpu (int16_t) allows values like 65536 to silently wrap to 0, bypassing bounds checks. The fix adds proper bounds validation via perf_env__get_cpu_topology() before accessing the heap structure. Patches are available in the stable Linux kernel tree.

Affected products

  • Linux Linux kernel Various stable branches (4.x through 7.x series)

Timeline

  • 2026-08-28: disclosed: CVE published
  • 2026-06-06: patched: Fix committed to upstream Linux kernel
  • 2026-07-24: patched: Fix backported to stable Linux branches

References

Related threats