CVE Database
/

CVE-2026-23014

Back to search

CVE-2026-23014

Published: Jan 28, 2026

Modified: May 23, 2026

PUBLISHED

CVSS v3.1

7.8

HIGH

Description

In the Linux kernel, the following vulnerability has been resolved: perf: Ensure swevent hrtimer is properly destroyed With the change to hrtimer_try_to_cancel() in perf_swevent_cancel_hrtimer() it appears possible for the hrtimer to still be active by the time the event gets freed. Make sure the event does a full hrtimer_cancel() on the free path by installing a perf_event::destroy handler.

VendorProductVersions

Linux

Linux

affected
eb3182ef0405ff2f6668fd3e5ff9883f60ce8801 - < deee9dfb111ab00f9dfd46c0c7e36656b80f5235
affected
eb3182ef0405ff2f6668fd3e5ff9883f60ce8801 - < ff5860f5088e9076ebcccf05a6ca709d5935cfa9
affected
6b8c512811644cf2f5eaf6f44e928683c54127f0
affected
6.17.8 - < 6.18

Linux

Linux

affected
6.18
unaffected
0 - < 6.18
unaffected
6.18.6 - <= 6.18.*
unaffected
6.19 - <= *

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector

Local

Attack Complexity

Low

Privileges Required

Low

User Interaction

None

Scope

Unchanged

Confidentiality

High

Integrity

High

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now