Description
In the Linux kernel, the following vulnerability has been resolved:

s390/perf_cpum_cf: Add missing array_index_nospec() to __hw_perf_event_init()

ev variable is userspace controlled via event->attr.config and used
as an array index after bounds checking, but without speculation
barriers.

Add the missing array_index_nospec() call to prevent speculative
execution.
Published: 2026-08-15
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

In the Linux kernel, the variable ev, set by userspace through event->attr.config, is used as an array index after bounds checking but without a speculative execution barrier. The missing array_index_nospec call allows the CPU to speculatively access array elements outside the intended bounds, creating a Spectre‑type side‑channel that could leak sensitive kernel data. Consequently an attacker with the ability to configure perf events could deduce confidential information through the speculative execution path.

Affected Systems

All Linux kernel versions that contain the vulnerable s390/perf_cpum_cf code and have not yet received the patch that restores proper speculation protection are affected. The flaw applies to any distribution shipping an unpatched kernel containing the referenced commit; no specific version range is listed, so any earlier kernel with this code is at risk.

Risk and Exploitability

The vulnerability can be exploited by local users who can set perf event configurations, providing a straightforward attack surface. The EPSS score of < 1% and the CVSS score of 5.5 indicate moderate likelihood and moderate severity, while the flaw is not listed in the CISA KEV catalog. Exploitation requires the attacker to trigger a speculatively executed out‑of‑bounds read and to observe the resulting microarchitectural changes. Given the CVSS score and attack vector, immediate action is recommended.

Generated by OpenCVE AI on August 18, 2026 at 14:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the kernel to a version that includes the commit adding array_index_nospec to __hw_perf_event_init()
  • If a kernel upgrade is not immediately possible, increase the kernel perf_event_paranoid setting to a high value to restrict unprivileged users from creating perf events
  • Reboot after applying the changes to ensure the new settings take effect and to flush any speculative state

Generated by OpenCVE AI on August 18, 2026 at 14:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 23 Aug 2026 13:15:00 +0000


Tue, 18 Aug 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Sat, 15 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: s390/perf_cpum_cf: Add missing array_index_nospec() to __hw_perf_event_init() ev variable is userspace controlled via event->attr.config and used as an array index after bounds checking, but without speculation barriers. Add the missing array_index_nospec() call to prevent speculative execution.
Title s390/perf_cpum_cf: Add missing array_index_nospec() to __hw_perf_event_init()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-08-23T12:47:04.750Z

Reserved: 2026-08-09T03:40:39.914Z

Link: CVE-2026-72236

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-15T06:21:50.633

Modified: 2026-08-23T13:16:42.093

Link: CVE-2026-72236

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-08-15T00:00:00Z

Links: CVE-2026-72236 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T14:15:07Z

Weaknesses