CVE-2026-80916
Received Received - Intake

Race Condition in Linux Kernel KCOV

Vulnerability report for CVE-2026-80916, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-09

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: kcov: fix data corruption and race conditions on PREEMPT_RT syzbot is reporting KCOV state corruption on PREEMPT_RT kernels, for the temporary storage used for saving/restoring remote KCOV state is currently allocated as the per-CPU area. On PREEMPT_RT kernels, softirq handlers run as preemptible task threads (e.g., ksoftirqd). If a softirq context preempts a task running a remote KCOV session, it safely saves the task's state into the per-CPU area. However, if that softirq thread is subsequently preempted by a higher- priority softirq thread on the same CPU, the second softirq will overwrite the same per-CPU area, permanently destroying the original task's KCOV state. Fix this data corruption by moving the temporary storage from the per-CPU area to the per-thread area. Since each softirq thread now owns its own task context, nested softirq preemption no longer causes data overwrites. Note that while the temporary storage is now on a per-thread basis, the per-CPU kcov_percpu_data.lock must be retained, for we need to ensure that kcov_remote_start() and kcov_remote_stop() operate atomically without racing against asynchronous interrupts that manipulate the current task's KCOV state. It is likely that GFP_KERNEL allocation by vmalloc_node() in kcov_init() has already called panic() before returning NULL, for there will be no OOM-killable userspace processes when __init function of built-in module runs. But this patch also fixes crashing the kernel when vmalloc_node() in kcov_init() returned NULL, for kcov_init() left per-CPU irq_area == NULL but kcov_remote_start() depends on per-CPU irq_area != NULL, resulting in (1) doing vmalloc() in kcov_remote_start() despite !in_task() context (2) out-of-array-bounds access if (1) succeeded but kcov->remote_size < CONFIG_KCOV_IRQ_AREA_SIZE (3) always leak memory allocated by (1), eventually killing all OOM-killable userspace processes problems.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-09
Generated
2026-09-30
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-29
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
linux linux_kernel *
linux_kernel linux_kernel *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Linux kernel involves data corruption and race conditions in the KCOV (Kernel Coverage) subsystem when running on PREEMPT_RT kernels. The issue occurs because temporary storage for remote KCOV state is stored in a per-CPU area, which can be overwritten if nested softirq threads preempt each other on the same CPU. This destroys the original task's KCOV state. The fix moves this storage to a per-thread area to prevent data loss.

Detection Guidance

This vulnerability is specific to the Linux kernel's KCOV feature on PREEMPT_RT kernels. Detection requires checking kernel logs for KCOV-related errors or crashes, particularly during softirq handling. No standard commands exist for direct detection as it involves kernel state corruption.

Impact Analysis

This vulnerability could lead to kernel crashes or memory leaks if exploited. It may cause system instability, data corruption, or denial of service by disrupting kernel subsystems that rely on KCOV for coverage tracking. Systems running PREEMPT_RT kernels with KCOV enabled are most at risk.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR, HIPAA, or similar standards. It is a kernel-level issue related to data corruption and race conditions in the KCOV subsystem on PREEMPT_RT kernels, which could lead to system instability or crashes but does not involve unauthorized data access or processing violations typical of compliance concerns.

Mitigation Strategies

Apply the kernel patch that moves temporary storage from per-CPU to per-thread area. Update to a fixed Linux kernel version where this issue is resolved. Monitor kernel logs for KCOV-related errors as an indicator of exploitation or corruption.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-80916. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart