PatchSiren cyber security CVE debrief
CVE-2026-72240 Linux CVE debrief
A reference leak was found in the Linux kernel's mfd: sm501 when platform_device_register() fails in sm501_register_device(). The issue was resolved by calling platform_device_put() before returning the error. This vulnerability affects Linux kernel developers and users who need to ensure their systems are up-to-date with the latest security patches. The vulnerability can be mitigated by applying patches for Linux kernel vulnerabilities to prevent potential reference leaks. The issue was identified by a static analysis tool and confirmed by manual review. Linux kernel developers and users should verify their systems for potential reference leaks and ensure they are up-to-date with the latest security patches.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-15
- Original CVE updated
- 2026-08-15
- Advisory published
- 2026-08-15
- Advisory updated
- 2026-08-15
Who should care
Linux kernel developers and users who need to ensure their systems are up-to-date with the latest security patches. This includes operators, platforms, vulnerability-management teams, and security teams that may be impacted by the vulnerability. They should review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance, and plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
Technical summary
The Linux kernel's mfd: sm501 has a reference leak vulnerability when platform_device_register() fails in sm501_register_device(). The issue was resolved by calling platform_device_put() before returning the error. This vulnerability affects Linux kernel developers and users who need to ensure their systems are up-to-date with the latest security patches. The vulnerability can be mitigated by applying patches for Linux kernel vulnerabilities to prevent potential reference leaks.
Defensive priority
Apply patches for Linux kernel vulnerabilities to prevent potential reference leaks.
Recommended defensive actions
- Apply the patch for Linux kernel mfd: sm501 reference leak vulnerability
- Review and update Linux kernel to the latest version
- Monitor Linux kernel updates for potential security patches
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
Evidence notes
The issue was identified by a static analysis tool and confirmed by manual review. The CVE record and NVD entry provide details on the vulnerability. Linux kernel developers and users should verify their systems for potential reference leaks and ensure they are up-to-date with the latest security patches. The vulnerability affects the Linux kernel's mfd: sm501 component, and defenders should review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-72240 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-72240
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-72240 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-72240
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/0baf9d43a7b7b43df2900bd8656e75b725028b6e
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/16a42c88c4667fa0bd944e438a667e059551f1f1
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/2ff8156fd500d54c61430b6834137fd0a07047ce
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/760a1029692f1d788dc11aa636a3bf432e58b240
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/8c2f0b42fc252e1bf1c7746447091a468e784ca1
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/a3e340d506c1036a747fb0972aebf1063f7ef30e
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/bbb1ecaed4ed7680e63d3a0f143f03de32de5d6e
416baaa9-dc9f-4396-8d5f-8c081fb06d67
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.