CVE-2026-72395: Linux
High severity, CVSS 7.1. EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: hwmon: (pmbus) Fix passing events to regulator core Sashiko reports: Commit 754bd2b4a084 ("hwmon: (pmbus/core) Protect regulator operations with mutex") introduced a worker to batch regulator events over time using atomic_or(). The delayed worker then passes the combined bitmask unmodified to regulator_notifier_call_chain(). The core regulator subsystem's regulator_handle_critical() function evaluates the event parameter using a strict switch statement. If multiple distinct faults occur before the worker runs (e.g., REGULATOR_EVENT_UNDER_VOLTAGE | REGULATOR_EVENT_OVER_CURRENT), the combined bitmask fails to match any case. This leaves the reason as NULL and completely bypasses the critical hw_protection_trigger(). Fix the problem by passing events bit by bit to the regulator event handler.
Affected products
- Linux Linux: from 6.6.143, before 6.6.145 (fixed in 6.6.145); from 6.12.92, before 6.12.97 (fixed in 6.12.97); from 6.18.21, before 6.18.40 (fixed in 6.18.40); from 6.19.11, before 6.20 (fixed in 6.20); from 7.0, before 7.1.5 (fixed in 7.1.5)
Published 2026-08-15. Last modified 2026-08-17.