
A new vulnerability with increased severity was disclosed for Linux Kernel (CVE-2026-23127) https://vuldb.com/?id.346097
Post summary
A new Linux Kernel vulnerability (CVE-2026-23127) has been disclosed with increased severity.
Signal is active with 3 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
In the Linux kernel, the following vulnerability has been resolved: perf: Fix refcount warning on event->mmap_count increment When calling refcount_inc(&event->mmap_count) inside perf_mmap_rb(), the following warning is triggered: refcount_t: addition on 0; use-after-free. WARNING: lib/refcount.c:25 PoC: struct perf_event_attr attr = {0}; int fd = syscall(__NR_perf_event_open, &attr, 0, -1, -1, 0); mmap(NULL, 0x3000, PROT_READ | PROT_WRITE, MAP_SHARED, fd, 0); int victim = syscall(__NR_perf_event_open, &attr, 0, -1, fd, PERF_FLAG_FD_OUTPUT); mmap(NULL, 0x3000, PROT_READ | PROT_WRITE, MAP_SHARED, victim, 0); This occurs when creating a group member event with the flag PERF_FLAG_FD_OUTPUT. The group leader should be mmap-ed and then mmap-ing the event triggers the warning. Since the event has copied the output_event in perf_event_set_output(), event->rb is set. As a result, perf_mmap_rb() calls refcount_inc(&event->mmap_count) when event->mmap_count = 0. Disallow the case when event->mmap_count = 0. This also prevents two events from updating the same user_page.
Priority
LOW
Exploitation
NONE
PoC
NONE
Patch
AVAILABLE
Momentum
NONE
If you run products in this scope, you should treat this CVE as relevant to your environment.
1 version affected across 1 product

A new vulnerability with increased severity was disclosed for Linux Kernel (CVE-2026-23127) https://vuldb.com/?id.346097
Post summary
A new Linux Kernel vulnerability (CVE-2026-23127) has been disclosed with increased severity.

CVE-2026-23127 In the Linux kernel, the following vulnerability has been resolved: perf: Fix refcount warning on event->mmap_count increment When calling refcount_inc(&event->mmap… https://www.cve.org/CVERecord?id=CVE-2026-23127
Post summary
CVE-2026-23127 was fixed in the Linux kernel with a patch that resolves a refcount warning on event->mmap_count increment; no PoC, exploit, or active exploitation is reported.

@vuldb CVE-2026-23127 with increased severity on linux kernel... not ideal timing with all the AI agents running on linux infrastructure lol
Post summary
A new CVE (CVE-2026-23127) for the Linux kernel is announced with heightened severity, but the post lacks details on exploitation or mitigation.
7 of 7 entries
| Part | Vendor | Product | Version | Target SW | Target HW |
|---|---|---|---|---|---|
| OS | linux | linux_kernel | - | - | - |
| OS | linux | linux_kernel | 6.19 | - | - |
| OS | linux | linux_kernel | 6.19 | - | - |
| OS | linux | linux_kernel | 6.19 | - | - |
| OS | linux | linux_kernel | 6.19 | - | - |
| OS | linux | linux_kernel | 6.19 | - | - |
| OS | linux | linux_kernel | 6.19 | - | - |