Answer in brief
CVE-2026-64556 records a Unknown severity vulnerability in perf/core: Detach event groups during remove_on_exec. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=2e498d0a74e5b88a6689ae1b811f247f91ff188e <4cdb1b3ab96eb1b7eb70bc5c82fede334bd60df2 || >=2e498d0a74e5b88a6689ae1b811f247f91ff188e <39358e856fb89e62e3c8d7389a2dc4ec33dbe90e || >=2e498d0a74e5b88a6689ae1b811f247f91ff188e <a2d5d3ee7b6e3953114726b1521e62123ab5b043 || >=2e498d0a74e5b88a6689ae1b811f247f91ff188e <06ccef0434e98058ddae7bcebc901f93d22b7653 || >=2e498d0a74e5b88a6689ae1b811f247f91ff188e <037a3c43edfb597665dd34457cd22b14692f2ba3 | 4cdb1b3ab96eb1b7eb70bc5c82fede334bd60df2, 39358e856fb89e62e3c8d7389a2dc4ec33dbe90e, a2d5d3ee7b6e3953114726b1521e62123ab5b043, 06ccef0434e98058ddae7bcebc901f93d22b7653, 037a3c43edfb597665dd34457cd22b14692f2ba3 |
| Linux/Linuxgeneric | 5.13 | Not reported |
Published upstream
Jul 29, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: perf/core: Detach event groups during remove_on_exec perf_event_remove_on_exec() removes events by calling perf_event_exit_event(). For top-level events, this removes the event from the context with DETACH_EXIT only. This can leave inconsistent group state when a removed event is a group leader and the group contains siblings without remove_on_exec. If the group was active, the surviving siblings can remain active and attached to the removed leader's sibling list, but are no longer represented by a valid group leader on the PMU context active lists. A later close of the removed leader uses DETACH_GROUP and can promote the still-active siblings from this stale group state. The next schedule-in can then add an already-linked active_list entry again, corrupting the PMU context active list. With DEBUG_LIST enabled, this is caught as a list_add double-add in merge_sched_in(). Fix this by detaching group relationships when remove_on_exec removes an event. This preserves the existing task-exit and revoke behavior, while ensuring surviving siblings are ungrouped before the removed event leaves the context.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2026-64556 records a Unknown severity vulnerability in perf/core: Detach event groups during remove_on_exec. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=2e498d0a74e5b88a6689ae1b811f247f91ff188e <4cdb1b3ab96eb1b7eb70bc5c82fede334bd60df2 || >=2e498d0a74e5b88a6689ae1b811f247f91ff188e <39358e856fb89e62e3c8d7389a2dc4ec33dbe90e || >=2e498d0a74e5b88a6689ae1b811f247f91ff188e <a2d5d3ee7b6e3953114726b1521e62123ab5b043 || >=2e498d0a74e5b88a6689ae1b811f247f91ff188e <06ccef0434e98058ddae7bcebc901f93d22b7653 || >=2e498d0a74e5b88a6689ae1b811f247f91ff188e <037a3c43edfb597665dd34457cd22b14692f2ba3 | 4cdb1b3ab96eb1b7eb70bc5c82fede334bd60df2, 39358e856fb89e62e3c8d7389a2dc4ec33dbe90e, a2d5d3ee7b6e3953114726b1521e62123ab5b043, 06ccef0434e98058ddae7bcebc901f93d22b7653, 037a3c43edfb597665dd34457cd22b14692f2ba3 |
| Linux/Linuxgeneric | 5.13 | Not reported |
Published upstream
Jul 29, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: perf/core: Detach event groups during remove_on_exec perf_event_remove_on_exec() removes events by calling perf_event_exit_event(). For top-level events, this removes the event from the context with DETACH_EXIT only. This can leave inconsistent group state when a removed event is a group leader and the group contains siblings without remove_on_exec. If the group was active, the surviving siblings can remain active and attached to the removed leader's sibling list, but are no longer represented by a valid group leader on the PMU context active lists. A later close of the removed leader uses DETACH_GROUP and can promote the still-active siblings from this stale group state. The next schedule-in can then add an already-linked active_list entry again, corrupting the PMU context active list. With DEBUG_LIST enabled, this is caught as a list_add double-add in merge_sched_in(). Fix this by detaching group relationships when remove_on_exec removes an event. This preserves the existing task-exit and revoke behavior, while ensuring surviving siblings are ungrouped before the removed event leaves the context.
Quoted source text, attributed separately from HOL analysis.