PatchSiren cyber security CVE debrief
CVE-2026-72088 Linux CVE debrief
A DMA mapping leak was found in the Linux kernel's hpsa driver on the IOACCEL2 reset path. If phys_disk->in_reset is set, the function returns directly without undoing the resources acquired for the command. The issue has been resolved by adding the missing error cleanup. This vulnerability affects Linux kernel developers and users who rely on the hpsa driver. The DMA mapping leak could potentially lead to resource exhaustion or other issues if not properly addressed. Further analysis is required to fully understand the issue and its potential impact. The Linux kernel's hpsa driver has a DMA mapping leak on the IOACCEL2 reset path. If phys_disk->in_reset is set, the function returns directly without undoing the resources acquired for the command. The issue has been resolved by adding the missing error cleanup. However, the current information available does not provide a comprehensive understanding of the vulnerability's scope, affected systems, or potential mitigations. Additional research and verification are necessary to determine the vulnerability's impact and to develop effective defensive measures.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-15
- Original CVE updated
- 2026-08-15
- Advisory published
- 2026-08-15
- Advisory updated
- 2026-08-15
Who should care
Linux kernel developers and users who rely on the hpsa driver should be aware of this vulnerability and take necessary steps to mitigate its impact. This includes reviewing and applying patches, monitoring system logs, and ensuring that the Linux kernel is up-to-date with the latest security patches. Additionally, system administrators and security teams should review their systems for potential exposure and implement compensating controls as needed.
Technical summary
The Linux kernel's hpsa driver has a DMA mapping leak on the IOACCEL2 reset path. If phys_disk->in_reset is set, the function returns directly without undoing the resources acquired for the command. The issue has been resolved by adding the missing error cleanup. This vulnerability affects Linux kernel developers and users who rely on the hpsa driver. The DMA mapping leak could potentially lead to resource exhaustion or other issues if not properly addressed.
Defensive priority
Medium
Recommended defensive actions
- Review and apply the patch for the hpsa driver in the Linux kernel
- Monitor system logs for potential issues related to the hpsa driver
- Ensure that the Linux kernel is up-to-date with the latest security patches
- Perform a thorough review of the affected system to identify potential exposure
- Implement compensating controls to mitigate potential impact
- Conduct regular security audits to detect and address vulnerabilities
- Track changes to the Linux kernel and hpsa driver to ensure timely updates and patches
Evidence notes
The CVE record and NVD entry provide limited information about the vulnerability. Further analysis is required to fully understand the issue and its potential impact. The Linux kernel's hpsa driver has a DMA mapping leak on the IOACCEL2 reset path. If phys_disk->in_reset is set, the function returns directly without undoing the resources acquired for the command. The issue has been resolved by adding the missing error cleanup. However, the current information available does not provide a comprehensive understanding of the vulnerability's scope, affected systems, or potential mitigations. Additional research and verification are necessary to determine the vulnerability's impact and to develop effective defensive measures.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-72088 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-72088
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-72088 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-72088
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/018cbce6ee158244bb76cf638e8e3054e240aea9
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/782e1bf48672be44265c48e14602696c3c8ed904
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/a61de4d7e22a9ab9a90094d0e180b378e09a1d2c
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/d495b403d5b357dfe506b963bd7a78ecd5c7b667
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/e166bafc483e927150cb9b5f286c9191ea0df84e
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/e7bde072cceefc564413b46d64017c47a2e9977d
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/fb40928c59329a50eadb3ce8bfd7a67f490a6212
416baaa9-dc9f-4396-8d5f-8c081fb06d67
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.