PatchSiren cyber security CVE debrief
CVE-2026-72063 Linux CVE debrief
The Linux kernel vulnerability CVE-2026-72063 was resolved by removing redundant pinctrl direction calls in the Tegra GPIO driver. The issue caused a sleep-in-atomic context warning due to a mutex lock in an atomic context. This vulnerability affects Linux kernel users and administrators, who should be aware of this issue and take necessary actions to prevent potential problems. The CVE record was published on 2026-08-15T06:21:15.887Z and has not been modified since then. The vulnerability was found by static analysis and confirmed through manual review of tegra_gpio_probe(), Tegra GPIO direction callbacks, and Tegra pinctrl ops.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-15
- Original CVE updated
- 2026-08-23
- Advisory published
- 2026-08-15
- Advisory updated
- 2026-08-23
Who should care
Linux kernel users and administrators should be aware of this vulnerability and take necessary actions to prevent potential issues. They should verify and apply patches to prevent potential sleep-in-atomic context issues. Reviewing and updating Linux kernel configurations to ensure Tegra GPIO and pinctrl operations are properly handled is also recommended. Additionally, monitoring Linux kernel updates and patches for potential issues related to Tegra GPIO and pinctrl is crucial. Affected product deployments in managed environments should be confirmed and assigned an owner for follow-up. Compensating controls for exposed systems should be reviewed while remediation is scheduled and verified. Relevant monitoring, detection, and logs for exposed assets should be checked for extra review. Exceptions, retested remediated assets, and closed items should be tracked only after evidence is documented. This includes reviewing the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance. Planning vendor-supported updates or mitigations through normal change control where exposure is confirmed is also essential. Tracking exceptions, retesting remediated assets, and closing the item only after evidence is documented are critical steps in managing this vulnerability effectively. The vulnerability affects Linux kernel users, particularly those with Tegra GPIO and pinctrl operations, and requires prompt attention to prevent potential issues. Linux kernel users should review compensating controls for exposed systems while remediation is scheduled and verified. Linux kernel users should check relevant monitoring, detection, and logs for exposed assets that need extra review. Linux kernel users should track exceptions, retest remediated assets, and close the item only after evidence is documented. Linux kernel users should confirm whether affected product deployments exist in managed environments and assign an owner for follow-up. Linux kernel users should review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance. Linux kernel users should plan vendor-supported updates or mitigations, and
Technical summary
The Linux kernel vulnerability CVE-2026-72063 was resolved by removing redundant pinctrl direction calls in the Tegra GPIO driver. The issue caused a sleep-in-atomic context warning due to a mutex lock in an atomic context. The Tegra GPIO driver directly programs the GPIO controller direction registers, making the additional pinctrl calls unnecessary. This change prevents potential sleep-in-atomic context issues in the Linux kernel.
Defensive priority
Linux kernel users should verify and apply patches to prevent potential sleep-in-atomic context issues.
Recommended defensive actions
- Verify Linux kernel version and apply patches to prevent potential sleep-in-atomic context issues.
- Review and update Linux kernel configurations to ensure Tegra GPIO and pinctrl operations are properly handled.
- Monitor Linux kernel updates and patches for potential issues related to Tegra GPIO and pinctrl.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
Evidence notes
The issue was found by static analysis and confirmed through manual review of tegra_gpio_probe(), Tegra GPIO direction callbacks, and Tegra pinctrl ops. A directed runtime validation and lockdep reported a sleep-in-atomic warning.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-72063 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-72063
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-72063 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-72063
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/628c63f96f4564fa145f602af2d41daf9532201f
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/ac761e66708d51dac35c4c7f1891ea991dc788f0
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/cd17c5a1d9f186b57e9e2949be427803b7110a5c
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/d3e91a95b2b0fc6336dbf3ec90d831a1654d2720
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/e57a4845b0da60a7b9f052160878097826320954
416baaa9-dc9f-4396-8d5f-8c081fb06d67
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.