Description
In the Linux kernel, the following vulnerability has been resolved:

ipmi: Remove all sysfs files on registration failure

ipmi_add_smi() creates the nr_users and nr_msgs files before trying to
create the maintenance_mode file. If that last creation fails, the error
path removes only nr_users before dropping the final reference to the
interface.

Remove nr_msgs as well so no sysfs attribute embedded in the freed
interface remains registered.
Published: 2026-09-11
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Orphaned sysfs entry may expose kernel information
Action: Immediate Patch
AI Analysis

Impact

In the Linux kernel’s IPMI subsystem, the function ipmi_add_smi() creates the sysfs files nr_users and nr_msgs before attempting to create maintenance_mode. When the final creation fails, the error path removes only nr_users, leaving nr_msgs registered on a freed IPMI interface. Based on the description, this orphaned sysfs attribute remains exposed under /sys/class/ipmi, allowing userspace programs that can read IPMI sysfs entries to access internal kernel state and possibly sensitive information.

Affected Systems

Any Linux kernel that includes the unpatched ipmi driver is affected. That includes all distributions that ship a kernel version containing this code before the patch was released. The vulnerability is inherent to the kernel source and does not depend on a specific flavor or vendor beyond the generic Linux kernel.

Risk and Exploitability

The vulnerability assigns a CVSS score of 7.8, classifying it as high severity. The EPSS score of less than 1% indicates a very low likelihood of exploitation in the wild, and the bug is not listed in the CISA KEV catalog. Attackers would need a condition that triggers the maintenance_mode creation failure, which may require privileged kernel execution or specific environmental factors. Based on the description, the exploit path is thus limited to environments where privileged users can read the orphaned sysfs entry, so while the potential impact could be significant, the practical risk remains low in typical non‑privileged deployments.

Generated by OpenCVE AI on September 21, 2026 at 03:04 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a kernel update that includes the ipmi driver fix
  • If an update is not yet available, blacklist the ipmi module by adding "blacklist ipmi" to /etc/modprobe.d or use the kernel parameter ipmi=off to prevent the driver from loading
  • As a temporary measure, manually remove any orphaned sysfs entries under /sys/class/ipmi to eliminate the unintended attribute exposure

Generated by OpenCVE AI on September 21, 2026 at 03:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:H'}

cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-825
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: ipmi: Remove all sysfs files on registration failure ipmi_add_smi() creates the nr_users and nr_msgs files before trying to create the maintenance_mode file. If that last creation fails, the error path removes only nr_users before dropping the final reference to the interface. Remove nr_msgs as well so no sysfs attribute embedded in the freed interface remains registered.
Title ipmi: Remove all sysfs files on registration failure
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-13T06:29:09.887Z

Reserved: 2026-08-26T14:34:25.812Z

Link: CVE-2026-81006

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:09.313

Modified: 2026-09-13T07:17:07.273

Link: CVE-2026-81006

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:42:58Z

Links: CVE-2026-81006 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T03:15:09Z

Weaknesses
  • CWE-825

    Expired Pointer Dereference