PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-72240 Linux CVE debrief

A reference leak was found in the Linux kernel's mfd: sm501 when platform_device_register() fails in sm501_register_device(). The issue was resolved by calling platform_device_put() before returning the error. This vulnerability affects Linux kernel developers and users who need to ensure their systems are up-to-date with the latest security patches. The vulnerability can be mitigated by applying patches for Linux kernel vulnerabilities to prevent potential reference leaks. The issue was identified by a static analysis tool and confirmed by manual review. Linux kernel developers and users should verify their systems for potential reference leaks and ensure they are up-to-date with the latest security patches.

Vendor
Linux
Product
Unknown
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-15
Original CVE updated
2026-08-15
Advisory published
2026-08-15
Advisory updated
2026-08-15

Who should care

Linux kernel developers and users who need to ensure their systems are up-to-date with the latest security patches. This includes operators, platforms, vulnerability-management teams, and security teams that may be impacted by the vulnerability. They should review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance, and plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.

Technical summary

The Linux kernel's mfd: sm501 has a reference leak vulnerability when platform_device_register() fails in sm501_register_device(). The issue was resolved by calling platform_device_put() before returning the error. This vulnerability affects Linux kernel developers and users who need to ensure their systems are up-to-date with the latest security patches. The vulnerability can be mitigated by applying patches for Linux kernel vulnerabilities to prevent potential reference leaks.

Defensive priority

Apply patches for Linux kernel vulnerabilities to prevent potential reference leaks.

Recommended defensive actions

  • Apply the patch for Linux kernel mfd: sm501 reference leak vulnerability
  • Review and update Linux kernel to the latest version
  • Monitor Linux kernel updates for potential security patches
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.

Evidence notes

The issue was identified by a static analysis tool and confirmed by manual review. The CVE record and NVD entry provide details on the vulnerability. Linux kernel developers and users should verify their systems for potential reference leaks and ensure they are up-to-date with the latest security patches. The vulnerability affects the Linux kernel's mfd: sm501 component, and defenders should review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-72240 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-72240

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-72240 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-72240

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/0baf9d43a7b7b43df2900bd8656e75b725028b6e

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/16a42c88c4667fa0bd944e438a667e059551f1f1

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/2ff8156fd500d54c61430b6834137fd0a07047ce

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/760a1029692f1d788dc11aa636a3bf432e58b240

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/8c2f0b42fc252e1bf1c7746447091a468e784ca1

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/a3e340d506c1036a747fb0972aebf1063f7ef30e

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/bbb1ecaed4ed7680e63d3a0f143f03de32de5d6e

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.