« Volver al listado

CVE-2026-72395

Estado: RecibidaAlta (7.1)—

In the Linux kernel, the following vulnerability has been resolved:

hwmon: (pmbus) Fix passing events to regulator core

Sashiko reports:

Commit 754bd2b4a084 ("hwmon: (pmbus/core) Protect regulator operations with mutex") introduced a worker to batch regulator events over time using atomic_or(). The delayed worker then passes the combined bitmask unmodified to regulator_notifier_call_chain().

The core regulator subsystem's regulator_handle_critical() function evaluates the event parameter using a strict switch statement.

Leer descripción completaMostrar menos

If multiple distinct faults occur before the worker runs (e.g., REGULATOR_EVENT_UNDER_VOLTAGE | REGULATOR_EVENT_OVER_CURRENT), the combined bitmask fails to match any case. This leaves the reason as NULL and completely bypasses the critical hw_protection_trigger().

Fix the problem by passing events bit by bit to the regulator event handler.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vulnerabilidad local (AV:L/PR:L) que permite eludir protecciones críticas de hardware en el kernel, causando negación de servicio por fallo de detección de fallos de voltaje/corriente.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-72395",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.1,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 5.2,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "b26849cffaa7c43355b82e9bef3725e786973a1a",
              "lessThan": "2106bf4056858fcce3624e0c51f6fee4d41d3f2f",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "acf04e2863132f6d9222f71f3a76fb9782cbe061",
              "lessThan": "48fe43666950efefb7ac5fbdc012c1b3604096bf",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "4e9d723d9f198b86f6882a84c501ba1f39e8d055",
              "lessThan": "489291b6b56978cc50d34e8e13f9636ea296ba8a",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "754bd2b4a084b90b5e7b630e1f423061a9b9b761",
              "lessThan": "b0ff6b6ae9c5183ef701ece7016698bde5a5bfba",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "754bd2b4a084b90b5e7b630e1f423061a9b9b761",
              "lessThan": "9ef7dacd44216bf5ea05c8aef49eba4d145f4047",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "2c77ae315f3ce9d2c8e1609be74c9358c1fe4e07",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "6.6.143",
              "lessThan": "6.6.145",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.12.92",
              "lessThan": "6.12.97",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.18.21",
              "lessThan": "6.18.40",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.19.11",
              "lessThan": "6.20",
              "versionType": "semver"
            }
          ],
          "programFiles": [
            "drivers/hwmon/pmbus/pmbus_core.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "7.0"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "7.0",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.6.145",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.97",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.40",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.1.5",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/hwmon/pmbus/pmbus_core.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-08-15T06:22:13.043",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/2106bf4056858fcce3624e0c51f6fee4d41d3f2f",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/489291b6b56978cc50d34e8e13f9636ea296ba8a",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/48fe43666950efefb7ac5fbdc012c1b3604096bf",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/9ef7dacd44216bf5ea05c8aef49eba4d145f4047",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/b0ff6b6ae9c5183ef701ece7016698bde5a5bfba",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (pmbus) Fix passing events to regulator core\n\nSashiko reports:\n\nCommit 754bd2b4a084 (\"hwmon: (pmbus/core) Protect regulator operations with\nmutex\") introduced a worker to batch regulator events over time using\natomic_or(). The delayed worker then passes the combined bitmask unmodified\nto regulator_notifier_call_chain().\n\nThe core regulator subsystem's regulator_handle_critical() function\nevaluates the event parameter using a strict switch statement. If\nmultiple distinct faults occur before the worker runs (e.g.,\nREGULATOR_EVENT_UNDER_VOLTAGE | REGULATOR_EVENT_OVER_CURRENT), the combined\nbitmask fails to match any case. This leaves the reason as NULL and\ncompletely bypasses the critical hw_protection_trigger().\n\nFix the problem by passing events bit by bit to the regulator event\nhandler."
    }
  ],
  "lastModified": "2026-08-17T06:19:05.997",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}