#VU124538 Memory corruption in Linux kernel - CVE-2026-23311
Published: March 25, 2026
Linux kernel
Linux Foundation
Description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper locking mechanism in the perf/core subsystem when handling event scheduling. A local user can trigger a pinned event failure that leads to invalid wait context handling, resulting in a kernel bug and system crash.
Exploitation does not require elevated privileges but operates within the context of the perf event subsystem.