{"api_version":"1","generated_at":"2026-09-04T01:07:26+00:00","cve":"CVE-2026-74753","urls":{"html":"https://cve.report/CVE-2026-74753","api":"https://cve.report/api/cve/CVE-2026-74753.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-74753","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-74753"},"summary":{"title":"perf: Reject exited events as group leaders","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nperf: Reject exited events as group leaders\n\nperf_event_remove_on_exec() sets remove-on-exec events to the EXIT state\nand detaches their group relationships.  The event's file descriptor can\nremain open, however, and perf_event_open() currently accepts that event\nas a group leader because its early validation rejects only REVOKED and\nDEAD events.\n\nA new sibling can consequently be linked to the detached leader.  When\nthe leader is closed, perf_group_detach() observes that its\nPERF_ATTACH_GROUP bit is already clear and skips the new sibling.  The\nsibling then retains a group_leader pointer to the freed event.\n\nReject group leaders in the EXIT state.  Perform the check while holding\nthe shared context mutex so that an exec in the target task cannot detach\nthe leader between validation and group attachment.\n\n[peterz: make the earlier test fully consistent]","state":"PUBLISHED","assigner":"Linux","published_at":"2026-08-26 15:16:54","updated_at":"2026-09-02 13:18:10"},"problem_types":[],"metrics":[{"version":"3.1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","score":"7.8","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"7.8","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","data":{"baseScore":7.8,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"}}],"references":[{"url":"https://git.kernel.org/stable/c/7ce010275c531475f9d6e7efb11b9e522c74ed2e","name":"https://git.kernel.org/stable/c/7ce010275c531475f9d6e7efb11b9e522c74ed2e","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/e593031ff19a9484e8a00bc47edd447187721846","name":"https://git.kernel.org/stable/c/e593031ff19a9484e8a00bc47edd447187721846","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/7a03413f31c196ab3894f988cdce0bb47b4fec42","name":"https://git.kernel.org/stable/c/7a03413f31c196ab3894f988cdce0bb47b4fec42","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/ce12e1170c0c78dffb9b28af6d287492ae7dd99d","name":"https://git.kernel.org/stable/c/ce12e1170c0c78dffb9b28af6d287492ae7dd99d","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/fa091f46c3833fb22384f10eade2b4e1e1d0b278","name":"https://git.kernel.org/stable/c/fa091f46c3833fb22384f10eade2b4e1e1d0b278","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-74753","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-74753","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 4cdb1b3ab96eb1b7eb70bc5c82fede334bd60df2 ce12e1170c0c78dffb9b28af6d287492ae7dd99d git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 39358e856fb89e62e3c8d7389a2dc4ec33dbe90e e593031ff19a9484e8a00bc47edd447187721846 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected a2d5d3ee7b6e3953114726b1521e62123ab5b043 7a03413f31c196ab3894f988cdce0bb47b4fec42 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 06ccef0434e98058ddae7bcebc901f93d22b7653 7ce010275c531475f9d6e7efb11b9e522c74ed2e git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 037a3c43edfb597665dd34457cd22b14692f2ba3 fa091f46c3833fb22384f10eade2b4e1e1d0b278 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 6.6.145 6.6.156 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 6.12.96 6.12.108 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 6.18.39 6.18.46 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 7.1.4 7.1.10 semver","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"74753","cve":"CVE-2026-74753","epss":"0.001280000","percentile":"0.027790000","score_date":"2026-09-03","updated_at":"2026-09-04 00:08:06"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["kernel/events/core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"ce12e1170c0c78dffb9b28af6d287492ae7dd99d","status":"affected","version":"4cdb1b3ab96eb1b7eb70bc5c82fede334bd60df2","versionType":"git"},{"lessThan":"e593031ff19a9484e8a00bc47edd447187721846","status":"affected","version":"39358e856fb89e62e3c8d7389a2dc4ec33dbe90e","versionType":"git"},{"lessThan":"7a03413f31c196ab3894f988cdce0bb47b4fec42","status":"affected","version":"a2d5d3ee7b6e3953114726b1521e62123ab5b043","versionType":"git"},{"lessThan":"7ce010275c531475f9d6e7efb11b9e522c74ed2e","status":"affected","version":"06ccef0434e98058ddae7bcebc901f93d22b7653","versionType":"git"},{"lessThan":"fa091f46c3833fb22384f10eade2b4e1e1d0b278","status":"affected","version":"037a3c43edfb597665dd34457cd22b14692f2ba3","versionType":"git"}]},{"defaultStatus":"unaffected","product":"Linux","programFiles":["kernel/events/core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"6.6.156","status":"affected","version":"6.6.145","versionType":"semver"},{"lessThan":"6.12.108","status":"affected","version":"6.12.96","versionType":"semver"},{"lessThan":"6.18.46","status":"affected","version":"6.18.39","versionType":"semver"},{"lessThan":"7.1.10","status":"affected","version":"7.1.4","versionType":"semver"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.6.156","versionStartIncluding":"6.6.145","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.12.108","versionStartIncluding":"6.12.96","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.18.46","versionStartIncluding":"6.18.39","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.1.10","versionStartIncluding":"7.1.4","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nperf: Reject exited events as group leaders\n\nperf_event_remove_on_exec() sets remove-on-exec events to the EXIT state\nand detaches their group relationships.  The event's file descriptor can\nremain open, however, and perf_event_open() currently accepts that event\nas a group leader because its early validation rejects only REVOKED and\nDEAD events.\n\nA new sibling can consequently be linked to the detached leader.  When\nthe leader is closed, perf_group_detach() observes that its\nPERF_ATTACH_GROUP bit is already clear and skips the new sibling.  The\nsibling then retains a group_leader pointer to the freed event.\n\nReject group leaders in the EXIT state.  Perform the check while holding\nthe shared context mutex so that an exec in the target task cannot detach\nthe leader between validation and group attachment.\n\n[peterz: make the earlier test fully consistent]"}],"metrics":[{"cvssV3_1":{"baseScore":7.8,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"scenarios":[{"lang":"en","value":"AV:L - The bug is reached only through local syscalls—perf_event_open(2) to create a remove_on_exec group leader and attach a sibling, execve(2) to move the leader to EXIT state, close(2) to free it, then ioctl/read on the sibling. There is no network, adjacent-wireless, or physical device entry path.\nAC:L - The attacker fully controls the deterministic sequence: open leader with remove_on_exec, exec, open sibling against the leader fd, close leader, then trigger group operations on the sibling. No race or condition outside attacker control is required; the stale group_leader pointer is created reliably.\nPR:L - A basic unprivileged local user can open per-task perf event groups on their own process with exclude_kernel=1 under the default sysctl_perf_event_paranoid=2, without CAP_PERFMON or init-namespace root. security_perf_event_open(PERF_SECURITY_OPEN) and perf_check_permission() allow this self-monitoring path.\nUI:N - Exploitation requires no action from another user or administrator beyond the attacker running their own syscalls (open group, exec, attach sibling, close leader, ioctl/read sibling). No victim must mount filesystems, open files, or interact with the system.\nS:U - Impact is confined to kernel perf/core heap corruption and privilege escalation within the same host kernel security authority. This is not a VM escape, IOMMU bypass, or cross-namespace boundary change; it is standard local kernel memory corruption.\nC:H - This is a use-after-free: after the EXIT-state leader is freed, the sibling retains group_leader pointing at freed memory, and perf_event_for_each(), __perf_effective_state(), and group reads/ioctls dereference the freed leader and its context, enabling arbitrary kernel memory disclosure via controlled reallocations.\nI:H - Freed perf_event/group_leader structures can be reallocated with attacker-controlled data, providing heap grooming primitives for arbitrary kernel writes and control-flow hijack. Memory corruption from following the stale group_leader pointer is exploitable beyond a simple crash.\nA:H - UAF dereferences of the freed group_leader reliably cause kernel paging faults, oops, or panic when the sibling is read, enabled, or ioctl'd (as in related perf group_leader UAF reproducers). UAF on attacker-influenceable perf_event objects causes full denial of service and potential system-wide unavailability."}]}],"providerMetadata":{"dateUpdated":"2026-09-02T12:49:47.692Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/ce12e1170c0c78dffb9b28af6d287492ae7dd99d"},{"url":"https://git.kernel.org/stable/c/e593031ff19a9484e8a00bc47edd447187721846"},{"url":"https://git.kernel.org/stable/c/7a03413f31c196ab3894f988cdce0bb47b4fec42"},{"url":"https://git.kernel.org/stable/c/7ce010275c531475f9d6e7efb11b9e522c74ed2e"},{"url":"https://git.kernel.org/stable/c/fa091f46c3833fb22384f10eade2b4e1e1d0b278"}],"title":"perf: Reject exited events as group leaders","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-74753","datePublished":"2026-08-26T14:37:00.168Z","dateReserved":"2026-08-15T05:44:03.931Z","dateUpdated":"2026-09-02T12:49:47.692Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-08-26 15:16:54","lastModifiedDate":"2026-09-02 13:18:10","problem_types":[],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"74753","Ordinal":"1","Title":"perf: Reject exited events as group leaders","CVE":"CVE-2026-74753","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"74753","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\nperf: Reject exited events as group leaders\n\nperf_event_remove_on_exec() sets remove-on-exec events to the EXIT state\nand detaches their group relationships.  The event's file descriptor can\nremain open, however, and perf_event_open() currently accepts that event\nas a group leader because its early validation rejects only REVOKED and\nDEAD events.\n\nA new sibling can consequently be linked to the detached leader.  When\nthe leader is closed, perf_group_detach() observes that its\nPERF_ATTACH_GROUP bit is already clear and skips the new sibling.  The\nsibling then retains a group_leader pointer to the freed event.\n\nReject group leaders in the EXIT state.  Perform the check while holding\nthe shared context mutex so that an exec in the target task cannot detach\nthe leader between validation and group attachment.\n\n[peterz: make the earlier test fully consistent]","Type":"Description","Title":"perf: Reject exited events as group leaders"}]}}}