CVE-2026-89460Medium· 5.5▾ SunlitA flaw was found in the Linux kernel. A local user can trigger a kernel panic by running the `perf stat` command while CPUs are being hotplugged. This occurs because the system fails to properly allocate CPU event structures for newly onli…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 30.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.2%
— → 4.4
none → medium
— → 4.4
none → medium
— → 4.4
none → medium
Last analysed / modified upstream
4.4 → 5.5
A flaw was found in the Linux kernel. A local user can trigger a kernel panic by running the perf stat command while CPUs are being hotplugged. This occurs because the system fails to properly allocate CPU event structures for newly online CPUs, leading to a null pointer dereference. Successful exploitation results in a Denial of Service (DoS) due to a system crash.
kernel: s390/cpum_cf: Handle CPU hotplug via prepare/dead callbacks — rated Moderate by Red Hat. Released 2026-09-11, updated 2026-09-16.
Affected:
No fix planned:
Not affected:
Out of support scope
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-89686High· 7.0kernel: nfsd: fix BUG_ON in nfsd4_alloc_layout_stateid on racing delegation revoke (CVE-2026-89686)
CVE-2026-89709High· 7.0kernel: lockd, nfsd: RCU-protect nlmsvc_ops dispatch (CVE-2026-89709)
CVE-2026-80963Medium· 5.5kernel: dm-stats: fix a crash if allocation of per-cpu data fails (CVE-2026-80963)
CVE-2026-80984Medium· 5.5kernel: net/smc: do not dereference an unset send buffer on the SMC-D teardown path (CVE-2026-80984)
CVE-2026-89442Medium· 5.5kernel: platform/x86: ISST: Validate socket ID in clos_assoc ioctl (CVE-2026-89442)
CVE-2026-89457Medium· 5.5kernel: s390/dasd: Guard sysfs discipline callbacks against unallocated private data (CVE-2026-89457)