CVE-2026-72236

Source
https://cve.org/CVERecord?id=CVE-2026-72236
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72236.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-72236
Downstream
Published
2026-08-15T05:54:25.891Z
Modified
2026-08-18T03:30:50.088156536Z
Summary
s390/perf_cpum_cf: Add missing array_index_nospec() to __hw_perf_event_init()
Details

In the Linux kernel, the following vulnerability has been resolved:

s390/perfcpumcf: Add missing arrayindexnospec() to _hwperfeventinit()

ev variable is userspace controlled via event->attr.config and used as an array index after bounds checking, but without speculation barriers.

Add the missing arrayindexnospec() call to prevent speculative execution.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72236.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
212188a596d17d519842ef2173150315735b54e1
Fixed
27206bb57c47bdbe33bccc78fa7f7e2a719a06b9
Fixed
a21f3615c88421df81060b6ff89220fd34094c4d
Fixed
fa1ebae4206e6afc8caa642e9eb1bbe39a9a724f
Fixed
f79dff8c721bbb1f3fc312ea55e0551c2cc28801
Fixed
49145bce539117db4b6e9e83c0e5ef528e361050

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72236.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.4.0
Fixed
6.6.145
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.97
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.40
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72236.json"