{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-74753","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-08-15T05:44:03.931Z","datePublished":"2026-08-26T14:37:00.168Z","dateUpdated":"2026-09-02T12:49:47.692Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-02T12:49:47.692Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nperf: Reject exited events as group leaders\n\nperf_event_remove_on_exec() sets remove-on-exec events to the EXIT state\nand detaches their group relationships.  The event's file descriptor can\nremain open, however, and perf_event_open() currently accepts that event\nas a group leader because its early validation rejects only REVOKED and\nDEAD events.\n\nA new sibling can consequently be linked to the detached leader.  When\nthe leader is closed, perf_group_detach() observes that its\nPERF_ATTACH_GROUP bit is already clear and skips the new sibling.  The\nsibling then retains a group_leader pointer to the freed event.\n\nReject group leaders in the EXIT state.  Perform the check while holding\nthe shared context mutex so that an exec in the target task cannot detach\nthe leader between validation and group attachment.\n\n[peterz: make the earlier test fully consistent]"}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The bug is reached only through local syscalls—perf_event_open(2) to create a remove_on_exec group leader and attach a sibling, execve(2) to move the leader to EXIT state, close(2) to free it, then ioctl/read on the sibling. There is no network, adjacent-wireless, or physical device entry path.\nAC:L - The attacker fully controls the deterministic sequence: open leader with remove_on_exec, exec, open sibling against the leader fd, close leader, then trigger group operations on the sibling. No race or condition outside attacker control is required; the stale group_leader pointer is created reliably.\nPR:L - A basic unprivileged local user can open per-task perf event groups on their own process with exclude_kernel=1 under the default sysctl_perf_event_paranoid=2, without CAP_PERFMON or init-namespace root. security_perf_event_open(PERF_SECURITY_OPEN) and perf_check_permission() allow this self-monitoring path.\nUI:N - Exploitation requires no action from another user or administrator beyond the attacker running their own syscalls (open group, exec, attach sibling, close leader, ioctl/read sibling). No victim must mount filesystems, open files, or interact with the system.\nS:U - Impact is confined to kernel perf/core heap corruption and privilege escalation within the same host kernel security authority. This is not a VM escape, IOMMU bypass, or cross-namespace boundary change; it is standard local kernel memory corruption.\nC:H - This is a use-after-free: after the EXIT-state leader is freed, the sibling retains group_leader pointing at freed memory, and perf_event_for_each(), __perf_effective_state(), and group reads/ioctls dereference the freed leader and its context, enabling arbitrary kernel memory disclosure via controlled reallocations.\nI:H - Freed perf_event/group_leader structures can be reallocated with attacker-controlled data, providing heap grooming primitives for arbitrary kernel writes and control-flow hijack. Memory corruption from following the stale group_leader pointer is exploitable beyond a simple crash.\nA:H - UAF dereferences of the freed group_leader reliably cause kernel paging faults, oops, or panic when the sibling is read, enabled, or ioctl'd (as in related perf group_leader UAF reproducers). UAF on attacker-influenceable perf_event objects causes full denial of service and potential system-wide unavailability."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["kernel/events/core.c"],"versions":[{"version":"4cdb1b3ab96eb1b7eb70bc5c82fede334bd60df2","lessThan":"ce12e1170c0c78dffb9b28af6d287492ae7dd99d","status":"affected","versionType":"git"},{"version":"39358e856fb89e62e3c8d7389a2dc4ec33dbe90e","lessThan":"e593031ff19a9484e8a00bc47edd447187721846","status":"affected","versionType":"git"},{"version":"a2d5d3ee7b6e3953114726b1521e62123ab5b043","lessThan":"7a03413f31c196ab3894f988cdce0bb47b4fec42","status":"affected","versionType":"git"},{"version":"06ccef0434e98058ddae7bcebc901f93d22b7653","lessThan":"7ce010275c531475f9d6e7efb11b9e522c74ed2e","status":"affected","versionType":"git"},{"version":"037a3c43edfb597665dd34457cd22b14692f2ba3","lessThan":"fa091f46c3833fb22384f10eade2b4e1e1d0b278","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["kernel/events/core.c"],"versions":[{"version":"6.6.145","lessThan":"6.6.156","status":"affected","versionType":"semver"},{"version":"6.12.96","lessThan":"6.12.108","status":"affected","versionType":"semver"},{"version":"6.18.39","lessThan":"6.18.46","status":"affected","versionType":"semver"},{"version":"7.1.4","lessThan":"7.1.10","status":"affected","versionType":"semver"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.6.145","versionEndExcluding":"6.6.156"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.12.96","versionEndExcluding":"6.12.108"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.18.39","versionEndExcluding":"6.18.46"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"7.1.4","versionEndExcluding":"7.1.10"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/ce12e1170c0c78dffb9b28af6d287492ae7dd99d"},{"url":"https://git.kernel.org/stable/c/e593031ff19a9484e8a00bc47edd447187721846"},{"url":"https://git.kernel.org/stable/c/7a03413f31c196ab3894f988cdce0bb47b4fec42"},{"url":"https://git.kernel.org/stable/c/7ce010275c531475f9d6e7efb11b9e522c74ed2e"},{"url":"https://git.kernel.org/stable/c/fa091f46c3833fb22384f10eade2b4e1e1d0b278"}],"title":"perf: Reject exited events as group leaders","x_generator":{"engine":"bippy-1.2.0"}}}}