CVE-2026-23014
Published: Jan 28, 2026
Modified: May 23, 2026
CVSS v3.1
7.8
Description
In the Linux kernel, the following vulnerability has been resolved: perf: Ensure swevent hrtimer is properly destroyed With the change to hrtimer_try_to_cancel() in perf_swevent_cancel_hrtimer() it appears possible for the hrtimer to still be active by the time the event gets freed. Make sure the event does a full hrtimer_cancel() on the free path by installing a perf_event::destroy handler.
| Vendor | Product | Versions |
|---|---|---|
Linux | Linux | affected eb3182ef0405ff2f6668fd3e5ff9883f60ce8801 - < deee9dfb111ab00f9dfd46c0c7e36656b80f5235affected eb3182ef0405ff2f6668fd3e5ff9883f60ce8801 - < ff5860f5088e9076ebcccf05a6ca709d5935cfa9affected 6b8c512811644cf2f5eaf6f44e928683c54127f0affected 6.17.8 - < 6.18 |
Linux | Linux | affected 6.18unaffected 0 - < 6.18unaffected 6.18.6 - <= 6.18.*unaffected 6.19 - <= * |
CVSS v3.1 Details
CVSS v3.1 Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now