Answer in brief
CVE-2026-80602 records a Unknown severity vulnerability in perf/x86/amd/lbr: Fix kernel address leakage. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=f4f925dae7419fc7a10af539c073871927ce3a24 <5be478c1e08981ca91b34de310d7e2638171d9d8 || >=f4f925dae7419fc7a10af539c073871927ce3a24 <208ecca408b1707ad86ea247d3d3e09d3606fc13 || >=f4f925dae7419fc7a10af539c073871927ce3a24 <5ab0eba9c8819506bcb72348fd701f8a9006f95e || >=f4f925dae7419fc7a10af539c073871927ce3a24 <fb3b76b5ad2ebad63dd76f8b65b624eaf638b73f || >=f4f925dae7419fc7a10af539c073871927ce3a24 <2a892294b83f541115c94b0bb637f39bef187657 | 5be478c1e08981ca91b34de310d7e2638171d9d8, 208ecca408b1707ad86ea247d3d3e09d3606fc13, 5ab0eba9c8819506bcb72348fd701f8a9006f95e, fb3b76b5ad2ebad63dd76f8b65b624eaf638b73f, 2a892294b83f541115c94b0bb637f39bef187657 |
| Linux/Linuxgeneric | 6.1 | Not reported |
Published upstream
Aug 28, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 28, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 28, 2026
In the Linux kernel, the following vulnerability has been resolved: perf/x86/amd/lbr: Fix kernel address leakage A user-only branch stack can contain branches that originate from the kernel. As a result, kernel addresses are exposed to user space even when PERF_SAMPLE_BRANCH_USER is requested. On AMD processors supporting X86_FEATURE_AMD_LBR_V2, perf can still report SYSRET/ERET entries for which the branch-from addresses are in the kernel. E.g. $ perf record -e cycles -o - -j any,save_type,u -- \ perf bench syscall basic --loop 1000 | \ perf script -i - -F brstack|tr ' ' '\n'| \ grep -E '0x[89a-f][0-9a-f]{15}' ... 0xffffffff81001268/0x717a90a38f1a/M/-/-/0/ERET/NON_SPEC_CORRECT_PATH 0xffffffff81001268/0x717a90a39157/M/-/-/0/ERET/NON_SPEC_CORRECT_PATH 0xffffffff81001268/0x717a90a2c628/M/-/-/0/ERET/NON_SPEC_CORRECT_PATH 0xffffffff81001268/0x717a90a41b60/M/-/-/0/ERET/NON_SPEC_CORRECT_PATH 0xffffffff81001268/0x717a90a260db/M/-/-/0/ERET/NON_SPEC_CORRECT_PATH 0xffffffff81001268/0x717a90a260db/M/-/-/0/ERET/NON_SPEC_CORRECT_PATH 0xffffffff81001268/0x717a8bef1c30/M/-/-/0/ERET/NON_SPEC_CORRECT_PATH 0xffffffff81001268/0x717a8e4d3c90/M/-/-/0/ERET/NON_SPEC_CORRECT_PATH ... The reason is that the hardware filter only considers the privilege level applicable to the branch target. Extend software filtering to also validate the branch-from addresses against br_sel, so that any branch record whose branch-from address is in the kernel is dropped when PERF_SAMPLE_BRANCH_USER is requested.
Quoted source text, attributed separately from HOL analysis.