๐Ÿ” CVE Alert

CVE-2026-80670

UNKNOWN 0.0

perf tools: Use perf_env__get_cpu_topology() in machine__resolve()

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: perf tools: Use perf_env__get_cpu_topology() in machine__resolve() machine__resolve() accesses env->cpu[al->cpu].socket_id after checking al->cpu >= 0 and env->cpu != NULL, but without validating al->cpu against env->nr_cpus_avail. Since al->cpu comes from the untrusted perf.data sample, a crafted file with a large CPU index causes an out-of-bounds heap read. Use perf_env__get_cpu_topology() which validates both NULL and bounds. Also bounds-check al->cpu before the cast to struct perf_cpu (int16_t): without this, values like 65536 silently truncate to 0, bypassing the accessor's internal check and returning CPU 0's topology.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Aug 28, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
0c4c4debb0adda4c18c158d95031dc2b9f637869 < b9e8406651dcc1c19238aad11861a758683525b4 0c4c4debb0adda4c18c158d95031dc2b9f637869 < eb266a14c16a93eb4db7b56a452d6be93f8bdcd4 0c4c4debb0adda4c18c158d95031dc2b9f637869 < 5484b43a0ec8231c36fba6ead654cb72dbba8b8f
Linux / Linux
4.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/b9e8406651dcc1c19238aad11861a758683525b4 git.kernel.org: https://git.kernel.org/stable/c/eb266a14c16a93eb4db7b56a452d6be93f8bdcd4 git.kernel.org: https://git.kernel.org/stable/c/5484b43a0ec8231c36fba6ead654cb72dbba8b8f