Input: ims-pcu - fix race condition in reset_device sysfs callback
Published Aug 15, 2026
5.5
MEDIUMCVSS 3.1
EPSS 0.21%
Description
The ims_pcu_reset_device() sysfs callback calls ims_pcu_execute_command() without acquiring pcu->cmd_mutex. This can lead to data races and corruption of the shared command buffer if triggered concurrently with other commands.
Acquire pcu->cmd_mutex before calling ims_pcu_execute_command().
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 3.10StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<3.10
- Version 6.1.178StatusunaffectedConstraints<=6.1.*
- Version 6.12.97StatusunaffectedConstraints<=6.12.*
- Version 6.18.40StatusunaffectedConstraints<=6.18.*
- Version 6.6.145StatusunaffectedConstraints<=6.6.*
- Version 7.1.5StatusunaffectedConstraints<=7.1.*
- Version 7.2StatusunaffectedConstraints<=*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux | unaffected |
| |||||||||||||||||||||||||||
| Linux | Linux | affected |
|
No data.
No data.
Red Hat Enterprise Linux 10
kernel
Not affected
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (12)
- https://access.redhat.com/security/cve/CVE-2026-72075 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2516338 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-59033 Advisory
- https://git.kernel.org/stable/c/025955847e1500ced4719ac178beff6a3b2f0e3c
- https://git.kernel.org/stable/c/0fb84b1a3cdc74c453abc5f961c7d318c267ea4c
- https://git.kernel.org/stable/c/129187ec3f868829f61f6f07381ca72fe642d0b7
- https://git.kernel.org/stable/c/411b8c4b274737c3bf08e1e025801161603cfffc
- https://git.kernel.org/stable/c/54c2237fc69541c75fe4cd321622ebb8ecc3587f
- https://git.kernel.org/stable/c/f516cba88bf952d847e5c96d0e87f17eaae7ee6f
- https://lore.kernel.org/linux-cve-announce/2026081520-CVE-2026-72075-9090@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2026-72075
- https://www.cve.org/CVERecord?id=CVE-2026-72075
Change history (0)
No recorded changes yet.