CVE-2026-80602
In the Linux kernel, the following vulnerability has been resolved:
perf/x86/amd/lbr: Fix kernel address leakage
A user-only branch stack can contain branches that originate from the kernel. As a result, kernel addresses are exposed to user space even when PERF_SAMPLE_BRANCH_USER is requested. On AMD processors supporting X86_FEATURE_AMD_LBR_V2, perf can still report SYSRET/ERET entries for which the branch-from addresses are in the kernel.
E.g.
The reason is that the hardware filter only considers the privilege level applicable to the branch target. Extend software filtering to also validate the branch-from addresses against br_sel, so that any branch record whose branch-from address is in the kernel is dropped when PERF_SAMPLE_BRANCH_USER is requested.
Detalles técnicos trazas, registros y código del informe original
$ perf record -e cycles -o - -j any,save_type,u -- \
perf bench syscall basic --loop 1000 | \
perf script -i - -F brstack|tr ' ' '\n'| \
grep -E '0x[89a-f][0-9a-f]{15}'
...
0xffffffff81001268/0x717a90a38f1a/M/-/-/0/ERET/NON_SPEC_CORRECT_PATH
0xffffffff81001268/0x717a90a39157/M/-/-/0/ERET/NON_SPEC_CORRECT_PATH
0xffffffff81001268/0x717a90a2c628/M/-/-/0/ERET/NON_SPEC_CORRECT_PATH
0xffffffff81001268/0x717a90a41b60/M/-/-/0/ERET/NON_SPEC_CORRECT_PATH
0xffffffff81001268/0x717a90a260db/M/-/-/0/ERET/NON_SPEC_CORRECT_PATH
0xffffffff81001268/0x717a90a260db/M/-/-/0/ERET/NON_SPEC_CORRECT_PATH
0xffffffff81001268/0x717a8bef1c30/M/-/-/0/ERET/NON_SPEC_CORRECT_PATH
0xffffffff81001268/0x717a8e4d3c90/M/-/-/0/ERET/NON_SPEC_CORRECT_PATH
...CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.21%
- Percentil entre todas las CVEs puntuadas: 10
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/208ecca408b1707ad86ea247d3d3e09d3606fc13
- https://git.kernel.org/stable/c/2a892294b83f541115c94b0bb637f39bef187657
- https://git.kernel.org/stable/c/5ab0eba9c8819506bcb72348fd701f8a9006f95e
- https://git.kernel.org/stable/c/5be478c1e08981ca91b34de310d7e2638171d9d8
- https://git.kernel.org/stable/c/fb3b76b5ad2ebad63dd76f8b65b624eaf638b73f
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-80602",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "f4f925dae7419fc7a10af539c073871927ce3a24",
"lessThan": "5be478c1e08981ca91b34de310d7e2638171d9d8",
"versionType": "git"
},
{
"status": "affected",
"version": "f4f925dae7419fc7a10af539c073871927ce3a24",
"lessThan": "208ecca408b1707ad86ea247d3d3e09d3606fc13",
"versionType": "git"
},
{
"status": "affected",
"version": "f4f925dae7419fc7a10af539c073871927ce3a24",
"lessThan": "5ab0eba9c8819506bcb72348fd701f8a9006f95e",
"versionType": "git"
},
{
"status": "affected",
"version": "f4f925dae7419fc7a10af539c073871927ce3a24",
"lessThan": "fb3b76b5ad2ebad63dd76f8b65b624eaf638b73f",
"versionType": "git"
},
{
"status": "affected",
"version": "f4f925dae7419fc7a10af539c073871927ce3a24",
"lessThan": "2a892294b83f541115c94b0bb637f39bef187657",
"versionType": "git"
}
],
"programFiles": [
"arch/x86/events/amd/lbr.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6.1"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "6.1",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver",
"lessThanOrEqual": "7.1.*"
},
{
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"arch/x86/events/amd/lbr.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-08-28T08:16:44.070",
"references": [
{
"url": "https://git.kernel.org/stable/c/208ecca408b1707ad86ea247d3d3e09d3606fc13",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/2a892294b83f541115c94b0bb637f39bef187657",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/5ab0eba9c8819506bcb72348fd701f8a9006f95e",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/5be478c1e08981ca91b34de310d7e2638171d9d8",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/fb3b76b5ad2ebad63dd76f8b65b624eaf638b73f",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nperf/x86/amd/lbr: Fix kernel address leakage\n\nA user-only branch stack can contain branches that originate from\nthe kernel. As a result, kernel addresses are exposed to user space\neven when PERF_SAMPLE_BRANCH_USER is requested. On AMD processors\nsupporting X86_FEATURE_AMD_LBR_V2, perf can still report SYSRET/ERET\nentries for which the branch-from addresses are in the kernel.\n\nE.g.\n\n $ perf record -e cycles -o - -j any,save_type,u -- \\\n perf bench syscall basic --loop 1000 | \\\n perf script -i - -F brstack|tr ' ' '\\n'| \\\n grep -E '0x[89a-f][0-9a-f]{15}'\n\n ...\n 0xffffffff81001268/0x717a90a38f1a/M/-/-/0/ERET/NON_SPEC_CORRECT_PATH\n 0xffffffff81001268/0x717a90a39157/M/-/-/0/ERET/NON_SPEC_CORRECT_PATH\n 0xffffffff81001268/0x717a90a2c628/M/-/-/0/ERET/NON_SPEC_CORRECT_PATH\n 0xffffffff81001268/0x717a90a41b60/M/-/-/0/ERET/NON_SPEC_CORRECT_PATH\n 0xffffffff81001268/0x717a90a260db/M/-/-/0/ERET/NON_SPEC_CORRECT_PATH\n 0xffffffff81001268/0x717a90a260db/M/-/-/0/ERET/NON_SPEC_CORRECT_PATH\n 0xffffffff81001268/0x717a8bef1c30/M/-/-/0/ERET/NON_SPEC_CORRECT_PATH\n 0xffffffff81001268/0x717a8e4d3c90/M/-/-/0/ERET/NON_SPEC_CORRECT_PATH\n ...\n\nThe reason is that the hardware filter only considers the privilege\nlevel applicable to the branch target. Extend software filtering to\nalso validate the branch-from addresses against br_sel, so that any\nbranch record whose branch-from address is in the kernel is dropped\nwhen PERF_SAMPLE_BRANCH_USER is requested."
}
],
"lastModified": "2026-08-28T08:16:44.070",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}