Description
In the Linux kernel, the following vulnerability has been resolved:

hwmon: (pmbus) Fix passing events to regulator core

Sashiko reports:

Commit 754bd2b4a084 ("hwmon: (pmbus/core) Protect regulator operations with
mutex") introduced a worker to batch regulator events over time using
atomic_or(). The delayed worker then passes the combined bitmask unmodified
to regulator_notifier_call_chain().

The core regulator subsystem's regulator_handle_critical() function
evaluates the event parameter using a strict switch statement. If
multiple distinct faults occur before the worker runs (e.g.,
REGULATOR_EVENT_UNDER_VOLTAGE | REGULATOR_EVENT_OVER_CURRENT), the combined
bitmask fails to match any case. This leaves the reason as NULL and
completely bypasses the critical hw_protection_trigger().

Fix the problem by passing events bit by bit to the regulator event
handler.
Published: 2026-08-15
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

In Linux kernel versions preceding the applied patch, the regulator subsystem can incorrectly combine multiple fault events into a single bitmask before handing them to the critical protection handler. When distinct events such as under‑voltage and over‑current occur before the batching worker runs, the resulting bitmask does not match any explicit case in the switch statement of regulator_handle_critical(). As a result, the fault reason is left NULL and the critical hardware protection routine is bypassed entirely. This failure to detect and react to hardware faults could allow a system to continue operating in a degraded or unsafe state, potentially leading to hardware damage or systemic instability.

Affected Systems

All Linux kernel distributions that do not include the commit that corrects the event batching logic are affected. This includes every kernel build prior to the introduction of the fix identified by commit 754bd2b4a084. Users of standard, unmodified Linux kernels without supplemental patches are thus vulnerable until the kernel is upgraded to a version containing the corrected regulator event handling.

Risk and Exploitability

The vulnerability carries a CVSS score of 7.1, with an EPSS score of less than 1%, indicating a low probability of exploitation. The likely attack vector, inferred from the fact that the fault bypass occurs within the kernel’s regulator subsystem, would involve privileged or internal actions related to hardware events; remote exploitation is unlikely. The risk remains significant because hardware protection could be bypassed, potentially leading to hardware damage or system instability. Since the vulnerability is not listed in the CISA KEV catalog, it is not known to be widely exploited, but the criticality of the hardware safety function justifies prompt remediation.

Generated by OpenCVE AI on August 22, 2026 at 07:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the kernel patch that corrects the regulator event batching bug, installing the kernel version that contains the fixed event handling logic (CWE-681).
  • Reboot the system to load the patched kernel, then verify that regulator events trigger the critical protection routine; monitor for under‑voltage and over‑current events to ensure correct bitmask handling (CWE-681).
  • Audit any custom PMBUS or regulator drivers for compliance with the updated subsystem, updating or replacing drivers that use improper event masking to prevent re‑introduction of the flaw (CWE-681).

Generated by OpenCVE AI on August 22, 2026 at 07:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 22 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-571
CWE-693

Wed, 19 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-681
References
Metrics threat_severity

None

threat_severity

Moderate


Mon, 17 Aug 2026 19:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-571
CWE-693

Mon, 17 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-658

Mon, 17 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H'}


Sat, 15 Aug 2026 11:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-658

Sat, 15 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: hwmon: (pmbus) Fix passing events to regulator core Sashiko reports: Commit 754bd2b4a084 ("hwmon: (pmbus/core) Protect regulator operations with mutex") introduced a worker to batch regulator events over time using atomic_or(). The delayed worker then passes the combined bitmask unmodified to regulator_notifier_call_chain(). The core regulator subsystem's regulator_handle_critical() function evaluates the event parameter using a strict switch statement. If multiple distinct faults occur before the worker runs (e.g., REGULATOR_EVENT_UNDER_VOLTAGE | REGULATOR_EVENT_OVER_CURRENT), the combined bitmask fails to match any case. This leaves the reason as NULL and completely bypasses the critical hw_protection_trigger(). Fix the problem by passing events bit by bit to the regulator event handler.
Title hwmon: (pmbus) Fix passing events to regulator core
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-08-17T05:43:38.599Z

Reserved: 2026-08-09T03:40:39.924Z

Link: CVE-2026-72395

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-15T06:22:13.043

Modified: 2026-08-17T06:19:05.997

Link: CVE-2026-72395

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-08-15T00:00:00Z

Links: CVE-2026-72395 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-22T08:00:13Z

Weaknesses
  • CWE-681

    Incorrect Conversion between Numeric Types