cbcvebase.
CVE-2026-23014
published 2026-01-28

CVE-2026-23014: In the Linux kernel, the following vulnerability has been resolved: perf: Ensure swevent hrtimer is properly destroyed With the change to…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.12%
1.8th percentile
In the Linux kernel, the following vulnerability has been resolved: perf: Ensure swevent hrtimer is properly destroyed With the change to hrtimer_try_to_cancel() in perf_swevent_cancel_hrtimer() it appears possible for the hrtimer to still be active by the time the event gets freed. Make sure the event does a full hrtimer_cancel() on the free path by installing a perf_event::destroy handler.

Affected

18 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.18.8-1 (forky)linux 6.18.8-1 (forky)
linuxlinux
linuxlinux
linuxlinux>= 6.17.8 < 6.186.18
linuxlinux>= eb3182ef0405ff2f6668fd3e5ff9883f60ce8801 < deee9dfb111ab00f9dfd46c0c7e36656b80f5235deee9dfb111ab00f9dfd46c0c7e36656b80f5235
linuxlinux>= eb3182ef0405ff2f6668fd3e5ff9883f60ce8801 < ff5860f5088e9076ebcccf05a6ca709d5935cfa9ff5860f5088e9076ebcccf05a6ca709d5935cfa9
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.18.8-16.18.8-1
linuxlinux_kernel>= 6.17.8 < 6.186.18
linuxlinux_kernel>= 6.18.0 < 6.18.66.18.6
linuxlinux_kernel>= 6.18.1 < 6.18.66.18.6
ubuntulinux-azure-6.17
ubuntulinux-azure-fde-6.17
ubuntulinux-gcp-6.17
ubuntulinux-oem-6.17
ubuntulinux-oracle-6.17
ubuntulinux-realtime-6.17

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.