CVE-2026-72237
CVE CVE-2026-72237EUVD EUVD-2026-59136Published 2026-08-15T05:54:26.000ZLast changed 2026-08-19T16:36:31.000Z
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: perf/x86/amd/brs: Fix kernel address leakage A user-only branch stack can contain branches that originate from the kernel. As a result, kernel addresses are exposed to user space even when PERF_SAMPLE_BRANCH_USER is requested. On AMD processors supporting X86_FEATURE_BRS (Zen 3 only), perf can still report entries such as SYSRET/interrupt returns for which the branch-from addresses are in the kernel. E.g. $ perf record -j any,u -c 4000 -e branch-brs -o - -- \ perf bench syscall basic --loop 1000 | \ perf script -i - -F brstack|tr ' ' '\n'| \ grep -E '0x[89a-f][0-9a-f]{15}' ... 0xffffffff810001c4/0x72e2e32955eb/-/-/-/0//- 0xffffffff810001c4/0x72e2d94a9821/-/-/-/0//- 0xffffffff810001c4/0x72e2d94ffa1b/-/-/-/0//- ... BRS provides no hardware branch filtering, so privilege level filtering is performed entirely in software. However, amd_brs_match_plm() only validates the branch-to address against the requested privilege levels. For branches from the kernel to user space, the branch-from address is left unchecked and is leaked. Extend the software filter to also validate the branch-from address, so that any branch record whose branch-from address is in the kernel is dropped when PERF_SAMPLE_BRANCH_USER is requested.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux 8910075d61a37e5b0d82e6c83ed9a0a31fe9ea08 <046f6244da9b68e463a849b21446b9424e531491; patch: 6.1.183; patch: 6.12.97; patch: 6.18.40; 8910075d61a37e5b0d82e6c83ed9a0a31fe9ea08 <4f949bc3913a6e3ce3b8574ac6ed1da8ec7a5ad1; patch: 7.1.5; patch: 0; patch: 6.6.145; 8910075d61a37e5b0d82e6c83ed9a0a31fe9ea08 <47915e855fb38b42133e31ba917d99565f862154; 8910075d61a37e5b0d82e6c83ed9a0a31fe9ea08 <ac44b4a3d6137489f8fa2e794b12e849c6b22eaa; patch: 7.2; 5.19; 8910075d61a37e5b0d82e6c83ed9a0a31fe9ea08 <90843d00dbc61220b66408ea0d8775cae9e51f70; 8910075d61a37e5b0d82e6c83ed9a0a31fe9ea08 <2e706be56f418718bb3ae66c0aa94f9b61150e6d
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.