Answer in brief
CVE-2026-72236 records a Unknown severity vulnerability in s390/perf_cpum_cf: Add missing array_index_nospec() to __hw_perf_event_init(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=212188a596d17d519842ef2173150315735b54e1 <27206bb57c47bdbe33bccc78fa7f7e2a719a06b9 || >=212188a596d17d519842ef2173150315735b54e1 <a21f3615c88421df81060b6ff89220fd34094c4d || >=212188a596d17d519842ef2173150315735b54e1 <fa1ebae4206e6afc8caa642e9eb1bbe39a9a724f || >=212188a596d17d519842ef2173150315735b54e1 <f79dff8c721bbb1f3fc312ea55e0551c2cc28801 || >=212188a596d17d519842ef2173150315735b54e1 <49145bce539117db4b6e9e83c0e5ef528e361050 | 27206bb57c47bdbe33bccc78fa7f7e2a719a06b9, a21f3615c88421df81060b6ff89220fd34094c4d, fa1ebae4206e6afc8caa642e9eb1bbe39a9a724f, f79dff8c721bbb1f3fc312ea55e0551c2cc28801, 49145bce539117db4b6e9e83c0e5ef528e361050 |
| Linux/Linuxgeneric | 3.4 | Not reported |
Published upstream
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 15, 2026
In the Linux kernel, the following vulnerability has been resolved: s390/perf_cpum_cf: Add missing array_index_nospec() to __hw_perf_event_init() ev variable is userspace controlled via event->attr.config and used as an array index after bounds checking, but without speculation barriers. Add the missing array_index_nospec() call to prevent speculative execution.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2026-72236 records a Unknown severity vulnerability in s390/perf_cpum_cf: Add missing array_index_nospec() to __hw_perf_event_init(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=212188a596d17d519842ef2173150315735b54e1 <27206bb57c47bdbe33bccc78fa7f7e2a719a06b9 || >=212188a596d17d519842ef2173150315735b54e1 <a21f3615c88421df81060b6ff89220fd34094c4d || >=212188a596d17d519842ef2173150315735b54e1 <fa1ebae4206e6afc8caa642e9eb1bbe39a9a724f || >=212188a596d17d519842ef2173150315735b54e1 <f79dff8c721bbb1f3fc312ea55e0551c2cc28801 || >=212188a596d17d519842ef2173150315735b54e1 <49145bce539117db4b6e9e83c0e5ef528e361050 | 27206bb57c47bdbe33bccc78fa7f7e2a719a06b9, a21f3615c88421df81060b6ff89220fd34094c4d, fa1ebae4206e6afc8caa642e9eb1bbe39a9a724f, f79dff8c721bbb1f3fc312ea55e0551c2cc28801, 49145bce539117db4b6e9e83c0e5ef528e361050 |
| Linux/Linuxgeneric | 3.4 | Not reported |
Published upstream
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 15, 2026
In the Linux kernel, the following vulnerability has been resolved: s390/perf_cpum_cf: Add missing array_index_nospec() to __hw_perf_event_init() ev variable is userspace controlled via event->attr.config and used as an array index after bounds checking, but without speculation barriers. Add the missing array_index_nospec() call to prevent speculative execution.
Quoted source text, attributed separately from HOL analysis.