PatchSiren cyber security CVE debrief
CVE-2026-23311 Linux CVE debrief
A local privilege context vulnerability exists in the Linux kernel's performance monitoring subsystem (perf/core). The flaw involves an invalid wait context where a wait-queue lock is incorrectly acquired while holding a perf-context lock, leading to a lockdep-detected bug. An attacker with local access could potentially trigger this condition to cause a denial of service. The vulnerability affects Linux kernel versions 6.15 through 6.18.16, 6.19 through 6.19.6, and 7.0-rc1. The fix restructures the wake-up mechanism to use irq_work instead of directly grabbing the wait-queue lock under the perf-context lock.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-03-25
- Original CVE updated
- 2026-05-26
- Advisory published
- 2026-03-25
- Advisory updated
- 2026-05-26
Who should care
Linux system administrators running kernel versions 6.15-6.18.16 or 6.19-6.19.6; security teams monitoring for local denial-of-service vectors; organizations using performance monitoring tools that rely on the kernel perf subsystem
Technical summary
The vulnerability exists in the perf/core subsystem's ctx_sched_in() function. When a pinned perf event fails during scheduling, the code attempts to wake up threads waiting on the ring buffer. This wake-up operation grabs a wait-queue lock while already holding the perf-context lock (ctx->lock), creating an invalid lock nesting context that lockdep detects. The fix moves the wake-up operation to irq_work, which defers the wait-queue lock acquisition to a safe context outside the perf-context lock critical section. The affected code paths are triggered during task scheduling events when performance monitoring is active.
Defensive priority
medium
Recommended defensive actions
- Apply the upstream kernel patches to affected systems
- Upgrade to Linux kernel 6.18.17 or later, or 6.19.7 or later
- For 7.0-rc1, apply the relevant stable patch or upgrade to a later release candidate
- Monitor kernel logs for lockdep warnings as indicators of exploitation attempts
- Restrict local access to performance monitoring capabilities where possible
Evidence notes
Lockdep detected the invalid wait context during event scheduling when a pinned event failed and attempted to wake threads in the ring buffer. The stack trace shows the issue occurs in __perf_event_task_sched_in with multiple locks held including rcu_read_lock, cpuctx_lock, and ctx->lock. The vulnerability is classified as CWE-667 (Improper Locking).
Sources and references
Verified primary and authoritative sources
-
CVE-2026-23311 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-23311
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-23311 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-23311
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/486ff5ad49bc50315bcaf6d45f04a33ef0a45ced
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/825f218ca70ef394c2b8546b313711d867b24584
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/c67ab059953e3b66cb17ddd6524c23f9e1f6526d
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.