CVE-2026-23248Patch(linux / linux_kernel)

LOWCVSS 7.8 · HIGH

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Patch linux linux_kernel systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In the Linux kernel, the following vulnerability has been resolved: perf/core: Fix refcount bug and potential UAF in perf_mmap Syzkaller reported a refcount_t: addition on 0; use-after-free warning in perf_mmap. The issue is caused by a race condition between a failing mmap() setup and a concurrent mmap() on a dependent event (e.g., using output redirection). In perf_mmap(), the ring_buffer (rb) is allocated and assigned to event->rb with the mmap_mutex held. The mutex is then released to perform map_range(). If map_range() fails, perf_mmap_close() is called to clean up. However, since the mutex was dropped, another thread attaching to this event (via inherited events or output redirection) can acquire the mutex, observe the valid event->rb pointer, and attempt to increment its reference count. If the cleanup path has already dropped the reference count to zero, this results in a use-after-free or refcount saturation warning. Fix this by extending the scope of mmap_mutex to cover the map_range() call. This ensures that the ring buffer initialization and mapping (or cleanup on failure) happens atomically effectively, preventing other threads from accessing a half-initialized or dying ring buffer.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • linux_kernel

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 4 total mentions across 1 day

Affected systems

Vendors
Products
linux_kernel

1 version affected across 1 product

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-03-18: 4Patch / Workaround · 2026-03-18: 2Technical Details · 2026-03-18: 203-18
Signal classification3 categories
Patch
250.0%
Disclosure
125.0%
General
125.0%
Referenced assets4 URLs
Full discourse4 posts
  • Brad Spengler@spendergrsec
    Patch

    CVE from today: https://lore.kernel.org/linux-cve-announce/2026031818-CVE-2026-23248-d0e1@gregkh/T/#u which if you were reading here, would have already seen 2 weeks ago (when we backported the fix to all of our stable kernels)

    Post summary

    The post announces CVE-2026-23248 but notes the fix was already backported to stable kernels two weeks prior.

    130912.2K
    4.4K followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-23248 In the Linux kernel, the following vulnerability has been resolved: perf/core: Fix refcount bug and potential UAF in perf_mmap Syzkaller reported a refcount_t: addi… https://www.cve.org/CVERecord?id=CVE-2026-23248

    Post summary

    The Linux kernel patch addresses a refcount bug that could lead to a use‑after‑free in perf_mmap; no exploitation or PoC is reported.

    00000132
    56.7K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-23248 Linux Kernel Perf Event Subsystem Use-After-Free Vulnerability in Ring Buffer Management https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-23248

    Post summary

    The text provides a brief announcement of CVE‑2026‑23248 with a link to a vulnerability database but contains no detailed technical or exploit information.

    0000042
    4.0K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-23248 - perf/core: Fix refcount bug and potential UAF in perf_mmap Intel Report: https://ift.tt/alwoPBf

    Post summary

    Intel announced CVE-2026-23248, a refcount bug that could lead to a use‑after‑free in perf_mmap. No PoC, exploit, or patch details are provided.

    0000027
    335 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
OSlinuxlinux_kernel---
OSlinuxlinux_kernel7.0--

Explore more