๐Ÿ” CVE Alert

CVE-2026-64300

UNKNOWN 0.0

perf/aux: Fix page UAF in map_range()

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: perf/aux: Fix page UAF in map_range() map_range() reads rb->aux_pages[], rb->aux_nr_pages and rb->aux_pgoff via perf_mmap_to_page() while holding only event->mmap_mutex. Those fields are serialized by rb->aux_mutex, and mmap_mutex is per event. Thus, two events sharing one rb via PERF_EVENT_IOC_SET_OUTPUT can race rb_alloc_aux() with map_range(), leading to a page-UAF scenario as follows: CPU 0 CPU 1 ===== ===== rb_alloc_aux() map_range() [1]: allocate rb->aux_pages[0] [2]: rb->aux_nr_pages++ [3]: perf_mmap_to_page() returns rb->aux_pages[0] [4]: map it as VM_PFNMAP [5]: rb->aux_pgoff = 1 munmap the page [6]: free rb->aux_pages[0] Pages mapped as VM_PFNMAP have no refcount protection, so CPU 1 holds a mapping to a freed physical frame. Fix this by taking rb->aux_mutex across the page walk in map_range().

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Jul 25, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
b709eb872e19a19607bbb6d2975bc264d59735cf < c8b7e113f7b61eef2f017e6329c27c2331058c5a b709eb872e19a19607bbb6d2975bc264d59735cf < 0cff05bd2186020f8706233e261016d149cc24db b709eb872e19a19607bbb6d2975bc264d59735cf < 5948aaf64f81f217a25dcc2bf6c0779bca19566c
Linux / Linux
6.14

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/c8b7e113f7b61eef2f017e6329c27c2331058c5a git.kernel.org: https://git.kernel.org/stable/c/0cff05bd2186020f8706233e261016d149cc24db git.kernel.org: https://git.kernel.org/stable/c/5948aaf64f81f217a25dcc2bf6c0779bca19566c