CVE-2026-80602

Source
https://cve.org/CVERecord?id=CVE-2026-80602
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80602.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-80602
Downstream
Published
2026-08-28T06:48:28.553Z
Modified
2026-08-30T03:48:22.922151234Z
Summary
perf/x86/amd/lbr: Fix kernel address leakage
Details

In the Linux kernel, the following vulnerability has been resolved:

perf/x86/amd/lbr: Fix kernel address leakage

A user-only branch stack can contain branches that originate from the kernel. As a result, kernel addresses are exposed to user space even when PERFSAMPLEBRANCHUSER is requested. On AMD processors supporting X86FEATUREAMDLBR_V2, perf can still report SYSRET/ERET entries for which the branch-from addresses are in the kernel.

E.g.

$ perf record -e cycles -o - -j any,save_type,u -- \ perf bench syscall basic --loop 1000 | \ perf script -i - -F brstack|tr ' ' '\n'| \ grep -E '0x[89a-f][0-9a-f]{15}'

... 0xffffffff81001268/0x717a90a38f1a/M/-/-/0/ERET/NONSPECCORRECTPATH 0xffffffff81001268/0x717a90a39157/M/-/-/0/ERET/NONSPECCORRECTPATH 0xffffffff81001268/0x717a90a2c628/M/-/-/0/ERET/NONSPECCORRECTPATH 0xffffffff81001268/0x717a90a41b60/M/-/-/0/ERET/NONSPECCORRECTPATH 0xffffffff81001268/0x717a90a260db/M/-/-/0/ERET/NONSPECCORRECTPATH 0xffffffff81001268/0x717a90a260db/M/-/-/0/ERET/NONSPECCORRECTPATH 0xffffffff81001268/0x717a8bef1c30/M/-/-/0/ERET/NONSPECCORRECTPATH 0xffffffff81001268/0x717a8e4d3c90/M/-/-/0/ERET/NONSPECCORRECTPATH ...

The reason is that the hardware filter only considers the privilege level applicable to the branch target. Extend software filtering to also validate the branch-from addresses against brsel, so that any branch record whose branch-from address is in the kernel is dropped when PERFSAMPLEBRANCHUSER is requested.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/80xxx/CVE-2026-80602.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
f4f925dae7419fc7a10af539c073871927ce3a24
Fixed
5be478c1e08981ca91b34de310d7e2638171d9d8
Fixed
208ecca408b1707ad86ea247d3d3e09d3606fc13
Fixed
5ab0eba9c8819506bcb72348fd701f8a9006f95e
Fixed
fb3b76b5ad2ebad63dd76f8b65b624eaf638b73f
Fixed
2a892294b83f541115c94b0bb637f39bef187657

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80602.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.1.0
Fixed
6.6.145
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.97
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.40
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80602.json"