Impact
The Linux kernel’s perf subsystem has a race condition between its mmap and munmap operations. A concurrent reviving mmap call can overlap with the final munmap of a ring buffer. The resulting use‑after‑free frees a buffer that another process still has mapped, allowing a local user to access freed kernel memory and manipulate it to gain root privileges, especially when kernel.perf_event_paranoid is set to 2.
Affected Systems
This flaw affects all Linux kernel releases that include the perf subsystem prior to the commit that reordered the reference‑count updates. Affected versions are not enumerated by the CNA, but any mainline kernel that has not yet applied the described patch is potentially impacted.
Risk and Exploitability
The CVSS score of 7.8 reflects a high severity local privilege escalation vulnerability. The EPSS score of <1% indicates a very low but non‑zero likelihood that the flaw will be actively exploited in the wild. The vulnerability is not listed in the CISA KEV catalog, so no known exploits are currently catalogued. Exploitation requires a local, unprivileged user on a Linux system that can coordinate concurrent perf mmap and munmap operations on a shared ring buffer. By creating a race between perf_mmap() and perf_mmap_close(), an attacker can trigger a use‑after‑free that frees a ring buffer that another process still holds, allowing access to freed kernel memory and exploitation for root privileges when kernel.perf_event_paranoid is set to 2.
OpenCVE Enrichment