CVE-2026-72314
CVE CVE-2026-72314EUVD EUVD-2026-59213Veröffentlicht 2026-08-15T05:55:29.000ZZuletzt geändert 2026-08-17T05:42:40.000ZCVSS 7.8
Was das Advisory beschreibt
In the Linux kernel, the following vulnerability has been resolved: regulator: core: regulator_lock_two() should test for EDEADLK not EDEADLOCK Compare against -EDEADLK, which is what ww_mutex_lock() actually returns and what every other deadlock check in this file already uses. Function regulator_lock_two() acquires two regulators via regulator_lock_nested() -> ww_mutex_lock(). On contention, ww_mutex_lock() returns -EDEADLK, which is the caller's signal to drop the lock it holds and retry the acquisition in the canonical order. However, regulator_lock_two() tests the return value against -EDEADLOCK rather than -EDEADLK. On most architectures, EDEADLK and EDEADLOCK are the same value, so the comparison happens to be correct and the bug is invisible. But on MIPS, SPARC, and PowerPC, those two errors have different values. The test is wrong: a genuine -EDEADLK backoff no longer matches -EDEADLOCK, so instead of unlocking and retrying, the code falls into WARN_ON(ret) and returns with only one of the two regulators locked. In practice, this is a bug only on MIPS, because the regulator core is not built or used on the other two platforms. In general, EDEADLK is preferred over EDEADLOCK for new code.
Quelle: EUVD (ENISA), im Wortlaut der Meldung.
Produkte, die das Advisory nennt
Diese Angaben stammen aus der Meldung selbst, nicht aus einer Prüfung durch uns.
- Linux — Linux cba6cfdc7c3f1516f0d08ddfb24e689af0932573 <e2063307ea3b6da74585129ba7b588e8243e2ef0; cba6cfdc7c3f1516f0d08ddfb24e689af0932573 <d38f8bd771c4999b797d7074b348cf201414bd34; patch: 0; cba6cfdc7c3f1516f0d08ddfb24e689af0932573 <29a7953e9adea6c7f9e64947745b79158e7cea7f; 6.2.15 <6.3; patch: 6.12.97; patch: 6.18.40; cba6cfdc7c3f1516f0d08ddfb24e689af0932573 <346e2d666a29ae7233c56b356a0487eb1d42589b; patch: 7.2; 6.4; 5.15.111 <5.15.212; 1e3056b8067c2e9b7741c4e588f0acacbe4bdafc <8e39aa63798ea0a797fd9341419f12ef91df3238; cdc042430ea9e07f77ce05a9d29e227dbdecc733; 5.4.243 <5.5; cba6cfdc7c3f1516f0d08ddfb24e689af0932573 <153d1b8b5bc30847eb70ad535f62f289aa9217e6; 06140d6dfe720d80566f792b4e28a9cd60a67970 <dc804f390fddd9c389edf0976356942e16878d8f; 435c65af581a61ca249bd8f717c3a147dc119f11; 5224ea575196db11c0a909a78ea426ccdb92f064; patch: 7.1.5; 6.1.28 <6.1.178; 6.3.2 <6.4; 5.10.180 <5.10.261; patch: 6.6.145; patch: 5.10.261; patch: 5.15.212; 849ab4cf182b38e562ffcc1b494d510e948822dd <0c305eac40470a224671858a215963b070f9b2a9; patch: 6.1.178
Die genannten Versionen sind die Angabe der Meldung. Patchlage vergleicht keine Versionsnummern und leitet aus ihnen keine Aussage ab — welche Version installiert ist, muss ein Mensch nachsehen.
Im Produktkatalog geführt
Für diese Produkte kann ein Bestand in Patchlage erfasst werden. Ein Advisory dazu erscheint am Morgen danach im Lagebericht.
- Linux — Linux
Betrifft das einen Ihrer Kundenbestände?
Diese Seite kann die Frage nicht beantworten — sie kennt Ihren Bestand nicht. Wer seine Umgebungen erfasst hat, bekommt die Antwort am Morgen nach der Veröffentlichung, zusammen mit einem Absatz, den er unverändert an den Kunden weitergeben kann.
28 Tage testenPatchlage meldet Treffer und Verdachtsfälle. Zu allem anderen sagt dieses System nichts — weder diese Seite noch der Lagebericht behauptet je, dass ein Bestand sicher ist.