Description
In the Linux kernel, the following vulnerability has been resolved:

regcache: Do not overwrite error code when finalizing cache after error

During regcache initialization, if an error occurs in the
cache_ops->populate callback, and if cache operations include an exit
callback, the error code from populate() is overwritten with the return
value from exit(). This hides the error condition from the caller of
regcache_init(), and can cause NULL pointer dereferences when the regcache
is later accessed.
Published: 2026-08-15
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

During the initialization of the Linux kernel register cache helper, an error returned by the populate callback can be overwritten by the exit callback’s return value, if both are defined. The original error is therefore hidden from the caller of regcache_init, making the failure invisible at that point. If the cache is later accessed, this missing error state can cause a null pointer dereference, which will crash the kernel and disrupt all processes on the affected system.

Affected Systems

All Linux kernel builds that use the regcache helper with both populate and exit callbacks and have not incorporated the patch found in the referenced git commits are affected. In practice, this includes any kernel version prior to the application of those changes, regardless of distribution. The defect is present in the kernel source tree wherever the regcache infrastructure is compiled in.

Risk and Exploitability

The EPSS score is less than 1%, and the vulnerability is not listed in CISA's KEV catalog, suggesting that public exploitation is unknown or limited. The CVSS score is 5.5, which indicates medium severity. Because the error occurs during regcache initialization, the likely attack vector is a local or privileged scenario in which an attacker can cause the driver or subsystem that uses regcache to perform an erroneous populate call. Once the error is hidden, an attacker could trigger use of the cached interface to provoke the crash. The overall threat is moderate to high for systems that allow such low‑level code execution but low for typical end‑users who cannot influence kernel initialization paths.

Generated by OpenCVE AI on August 22, 2026 at 06:18 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the running Linux kernel to a release that includes the regcache error-code preservation fix referenced in the supplied git commit URLs.
  • If a kernel update cannot be performed immediately, apply a local patch to the regcache source: copy the original error code before the exit callback, invoke exit, then restore the original error code if the returned value is non‑zero.
  • After applying the patch or upgrading, reboot the system or restart any affected services to clear stale cache entries and verify that regcache initialization reporting now reflects actual errors.

Generated by OpenCVE AI on August 22, 2026 at 06:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 22 Aug 2026 04:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-690

Thu, 20 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Low


Sat, 15 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-690

Sat, 15 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: regcache: Do not overwrite error code when finalizing cache after error During regcache initialization, if an error occurs in the cache_ops->populate callback, and if cache operations include an exit callback, the error code from populate() is overwritten with the return value from exit(). This hides the error condition from the caller of regcache_init(), and can cause NULL pointer dereferences when the regcache is later accessed.
Title regcache: Do not overwrite error code when finalizing cache after error
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-08-17T05:14:57.028Z

Reserved: 2026-08-09T03:40:39.932Z

Link: CVE-2026-72453

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-15T06:22:19.290

Modified: 2026-08-17T06:19:12.920

Link: CVE-2026-72453

cve-icon Redhat

Severity : Low

Publid Date: 2026-08-15T00:00:00Z

Links: CVE-2026-72453 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-22T06:30:04Z

Weaknesses