CVE-2026-72152: Linux

EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: tpm: tpm_tis_spi: Use wait_woken() in wait_for_tmp_stat() wait_event_interruptible_timeout() evaluates its condition after setting the current task state to TASK_INTERRUPTIBLE. With CONFIG_DEBUG_ATOMIC_SLEEP this triggers a warning when the IRQ wait path is used: tpm_tis_status() tpm_tis_spi_read_bytes() tpm_tis_spi_transfer_full() spi_bus_lock() mutex_lock() Address this with the following measures: 1. Call wait_tpm_stat_cond() only while tasking is running. 2. Use wait_woken() to wait for changes.

Affected products

  • Linux Linux: from 4.9.128, before 4.10 (fixed in 4.10); from 4.14.71, before 4.15 (fixed in 4.15); from 4.18.9, before 4.19 (fixed in 4.19); from 4.19, before 5.10.266 (fixed in 5.10.266); from 5.11, before 5.15.217 (fixed in 5.15.217); from 5.16, before 6.1.178 (fixed in 6.1.178); …

Published 2026-08-15. Last modified 2026-08-23.