« Volver al listado

CVE-2026-72145

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

platform/x86/intel/tpmi: use cleanup helpers in mem_write()

In mem_write(), the temporary array returned by parse_int_array_user() must be released on all exit paths. Convert the array variable to use cleanup.h scope-based cleanup so it is freed automatically on return.

This also moves the array declaration next to parse_int_array_user() as required by cleanup.h usage guidelines.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-72145",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "8e0a2fc68ec369f2b6755994da1d318d0898a9d9",
              "lessThan": "2137f21542900233a42bf00578817f9b8dfecadc",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "8e0a2fc68ec369f2b6755994da1d318d0898a9d9",
              "lessThan": "a221557958e3a82d8565729d445a7385963f30b6",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/platform/x86/intel/vsec_tpmi.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "7.1"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "7.1",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "7.1.5",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/platform/x86/intel/vsec_tpmi.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-08-15T06:21:32.167",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/2137f21542900233a42bf00578817f9b8dfecadc",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/a221557958e3a82d8565729d445a7385963f30b6",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nplatform/x86/intel/tpmi: use cleanup helpers in mem_write()\n\nIn mem_write(), the temporary array returned by\nparse_int_array_user() must be released on all exit paths.\nConvert the array variable to use cleanup.h scope-based\ncleanup so it is freed automatically on return.\n\nThis also moves the array declaration next to\nparse_int_array_user() as required by cleanup.h usage\nguidelines."
    }
  ],
  "lastModified": "2026-08-17T06:18:14.577",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}