0.0
NA
CVE-2026-72236
s390/perf_cpum_cf: Add missing array_index_nospec() to __hw_perf_event_init()
Description

In the Linux kernel, the following vulnerability has been resolved: s390/perf_cpum_cf: Add missing array_index_nospec() to __hw_perf_event_init() ev variable is userspace controlled via event->attr.config and used as an array index after bounds checking, but without speculation barriers. Add the missing array_index_nospec() call to prevent speculative execution.

INFO

Published Date :

Aug. 15, 2026, 6:21 a.m.

Last Modified :

Aug. 17, 2026, 6:18 a.m.

Remotely Exploit :

No

Source :

416baaa9-dc9f-4396-8d5f-8c081fb06d67
Affected Products

The following products are affected by CVE-2026-72236 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below.

ID Vendor Product Action
1 Linux linux_kernel
Solution
Apply kernel patch to prevent speculative execution using array_index_nospec().
  • Update the Linux kernel.
  • Apply the patch for s390/perf_cpum_cf.
  • Ensure array_index_nospec() is used.
CWE - Common Weakness Enumeration

While CVE identifies specific instances of vulnerabilities, CWE categorizes the common flaws or weaknesses that can lead to vulnerabilities. CVE-2026-72236 is associated with the following CWEs:

Common Attack Pattern Enumeration and Classification (CAPEC)

Common Attack Pattern Enumeration and Classification (CAPEC) stores attack patterns, which are descriptions of the common attributes and approaches employed by adversaries to exploit the CVE-2026-72236 weaknesses.

We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).

Results are limited to the first 15 repositories due to potential performance issues.

The following list is the news that have been mention CVE-2026-72236 vulnerability anywhere in the article.

The following table lists the changes that have been made to the CVE-2026-72236 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.

  • CVE Modified by 416baaa9-dc9f-4396-8d5f-8c081fb06d67

    Aug. 17, 2026

    Action Type Old Value New Value
    Changed Affected [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '212188a596d17d519842ef2173150315735b54e1', 'lessThan': '27206bb57c47bdbe33bccc78fa7f7e2a719a06b9', 'versionType': 'git'}, {'status': 'affected', 'version': '212188a596d17d519842ef2173150315735b54e1', 'lessThan': 'a21f3615c88421df81060b6ff89220fd34094c4d', 'versionType': 'git'}, {'status': 'affected', 'version': '212188a596d17d519842ef2173150315735b54e1', 'lessThan': 'fa1ebae4206e6afc8caa642e9eb1bbe39a9a724f', 'versionType': 'git'}, {'status': 'affected', 'version': '212188a596d17d519842ef2173150315735b54e1', 'lessThan': 'f79dff8c721bbb1f3fc312ea55e0551c2cc28801', 'versionType': 'git'}, {'status': 'affected', 'version': '212188a596d17d519842ef2173150315735b54e1', 'lessThan': '49145bce539117db4b6e9e83c0e5ef528e361050', 'versionType': 'git'}], 'programFiles': ['arch/s390/kernel/perf_cpum_cf.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '3.4'}, {'status': 'unaffected', 'version': '0', 'lessThan': '3.4', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '6.6.145', 'versionType': 'semver', 'lessThanOrEqual': '6.6.*'}, {'status': 'unaffected', 'version': '6.12.97', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.40', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.1.5', 'versionType': 'semver', 'lessThanOrEqual': '7.1.*'}, {'status': 'unaffected', 'version': '7.2-rc4', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['arch/s390/kernel/perf_cpum_cf.c'], 'defaultStatus': 'affected'}] [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '212188a596d17d519842ef2173150315735b54e1', 'lessThan': '27206bb57c47bdbe33bccc78fa7f7e2a719a06b9', 'versionType': 'git'}, {'status': 'affected', 'version': '212188a596d17d519842ef2173150315735b54e1', 'lessThan': 'a21f3615c88421df81060b6ff89220fd34094c4d', 'versionType': 'git'}, {'status': 'affected', 'version': '212188a596d17d519842ef2173150315735b54e1', 'lessThan': 'fa1ebae4206e6afc8caa642e9eb1bbe39a9a724f', 'versionType': 'git'}, {'status': 'affected', 'version': '212188a596d17d519842ef2173150315735b54e1', 'lessThan': 'f79dff8c721bbb1f3fc312ea55e0551c2cc28801', 'versionType': 'git'}, {'status': 'affected', 'version': '212188a596d17d519842ef2173150315735b54e1', 'lessThan': '49145bce539117db4b6e9e83c0e5ef528e361050', 'versionType': 'git'}], 'programFiles': ['arch/s390/kernel/perf_cpum_cf.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '3.4'}, {'status': 'unaffected', 'version': '0', 'lessThan': '3.4', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '6.6.145', 'versionType': 'semver', 'lessThanOrEqual': '6.6.*'}, {'status': 'unaffected', 'version': '6.12.97', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.40', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.1.5', 'versionType': 'semver', 'lessThanOrEqual': '7.1.*'}, {'status': 'unaffected', 'version': '7.2', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['arch/s390/kernel/perf_cpum_cf.c'], 'defaultStatus': 'affected'}]
  • New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67

    Aug. 15, 2026

    Action Type Old Value New Value
    Added Affected [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '212188a596d17d519842ef2173150315735b54e1', 'lessThan': '27206bb57c47bdbe33bccc78fa7f7e2a719a06b9', 'versionType': 'git'}, {'status': 'affected', 'version': '212188a596d17d519842ef2173150315735b54e1', 'lessThan': 'a21f3615c88421df81060b6ff89220fd34094c4d', 'versionType': 'git'}, {'status': 'affected', 'version': '212188a596d17d519842ef2173150315735b54e1', 'lessThan': 'fa1ebae4206e6afc8caa642e9eb1bbe39a9a724f', 'versionType': 'git'}, {'status': 'affected', 'version': '212188a596d17d519842ef2173150315735b54e1', 'lessThan': 'f79dff8c721bbb1f3fc312ea55e0551c2cc28801', 'versionType': 'git'}, {'status': 'affected', 'version': '212188a596d17d519842ef2173150315735b54e1', 'lessThan': '49145bce539117db4b6e9e83c0e5ef528e361050', 'versionType': 'git'}], 'programFiles': ['arch/s390/kernel/perf_cpum_cf.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '3.4'}, {'status': 'unaffected', 'version': '0', 'lessThan': '3.4', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '6.6.145', 'versionType': 'semver', 'lessThanOrEqual': '6.6.*'}, {'status': 'unaffected', 'version': '6.12.97', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.40', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.1.5', 'versionType': 'semver', 'lessThanOrEqual': '7.1.*'}, {'status': 'unaffected', 'version': '7.2-rc4', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['arch/s390/kernel/perf_cpum_cf.c'], 'defaultStatus': 'affected'}]
    Added Description In the Linux kernel, the following vulnerability has been resolved: s390/perf_cpum_cf: Add missing array_index_nospec() to __hw_perf_event_init() ev variable is userspace controlled via event->attr.config and used as an array index after bounds checking, but without speculation barriers. Add the missing array_index_nospec() call to prevent speculative execution.
    Added Reference https://git.kernel.org/stable/c/27206bb57c47bdbe33bccc78fa7f7e2a719a06b9
    Added Reference https://git.kernel.org/stable/c/49145bce539117db4b6e9e83c0e5ef528e361050
    Added Reference https://git.kernel.org/stable/c/a21f3615c88421df81060b6ff89220fd34094c4d
    Added Reference https://git.kernel.org/stable/c/f79dff8c721bbb1f3fc312ea55e0551c2cc28801
    Added Reference https://git.kernel.org/stable/c/fa1ebae4206e6afc8caa642e9eb1bbe39a9a724f
EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days. Following chart shows the EPSS score history of the vulnerability.