CVE-2026-72075
In the Linux kernel, the following vulnerability has been resolved: Input: ims-pcu - fix race condition in reset_device sysfs callback The ims_pcu_reset_device() sysfs callback calls ims_pcu_execute_command() without acquiring pcu->cmd_mutex.
Does this matter?
Not yet scored. NVD analysis is pending; check back once CVSS and EPSS values are published.
Description
In the Linux kernel, the following vulnerability has been resolved: Input: ims-pcu - fix race condition in reset_device sysfs callback The ims_pcu_reset_device() sysfs callback calls ims_pcu_execute_command() without acquiring pcu->cmd_mutex. This can lead to data races and corruption of the shared command buffer if triggered concurrently with other commands. Acquire pcu->cmd_mutex before calling ims_pcu_execute_command().
- CVSS
- Not yet scored
- EPSS
- 0.21% probability · 12th percentile
- CISA KEV
- Not listed
- Source
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
References
- https://git.kernel.org/stable/c/025955847e1500ced4719ac178beff6a3b2f0e3c
- https://git.kernel.org/stable/c/0fb84b1a3cdc74c453abc5f961c7d318c267ea4c
- https://git.kernel.org/stable/c/129187ec3f868829f61f6f07381ca72fe642d0b7
- https://git.kernel.org/stable/c/411b8c4b274737c3bf08e1e025801161603cfffc
- https://git.kernel.org/stable/c/54c2237fc69541c75fe4cd321622ebb8ecc3587f
- https://git.kernel.org/stable/c/f516cba88bf952d847e5c96d0e87f17eaae7ee6f
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.