CVE-2026-72236EPSS p12.8%
CVE-2026-72236CVE-2026-72236
Description
In the Linux kernel, the following vulnerability has been resolved:
s390/perf_cpum_cf: Add missing array_index_nospec() to __hw_perf_event_init()
ev variable is userspace controlled via event->attr.config and used
as an array index after bounds checking, but without speculation
barriers.
Add the missing array_index_nospec() call to prevent speculative
execution.
Scoring
| EPSS | 0.23% probability of exploitation · percentile 12.8% · 2026-10-06T12:00:23Z |
| Last modified | 2026-08-23 |