CVE-2026-72143: Linux

High severity, CVSS 7.1. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: platform/x86: ISST: Restore SST-PP control to all domains The SST-PP control offset is only restored to power domain 0 after resume. During suspend, control values are read and stored for all power domains. Use pd_info->sst_base instead of power_domain_info->sst_base, which only points to power domain 0 base address.

Affected products

  • Linux Linux: from 6.18.16, before 6.18.40 (fixed in 6.18.40); from 6.19.6, before 6.20 (fixed in 6.20); from 7.0, before 7.1.5 (fixed in 7.1.5)

Published 2026-08-15. Last modified 2026-08-17.