CVE-2026-72151
CVE CVE-2026-72151EUVD EUVD-2026-58909Published 2026-08-15T05:53:22.000ZLast changed 2026-08-17T05:41:00.000ZCVSS 8.4
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: tpm: tpm2-sessions: wait for async KPP completion in tpm_buf_append_salt tpm_buf_append_salt() in drivers/char/tpm/tpm2-sessions.c calls crypto_kpp_generate_public_key() and crypto_kpp_compute_shared_secret() without installing a completion callback, discards both return values, and immediately frees the kpp_request via kpp_request_free(). When the resolved ecdh-nist-p256 KPP backend is asynchronous (atmel-ecc, HPRE, keembay-ocs), either operation returns -EINPROGRESS and the deferred completion worker dereferences the freed request. The path fires automatically from the hwrng_fillfn kernel thread via tpm_get_random -> tpm2_get_random -> tpm2_start_auth_session -> tpm_buf_append_salt on every entropy poll, without any userland action. Install crypto_req_done as the completion callback, wrap both KPP operations in crypto_wait_req(), and propagate errors to the caller. The wait is a no-op for synchronous backends.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux patch: 7.1.5; 6.10; 1085b8276bb4239daa7008f0dcd5c973e4bd690f <111e520efbe82b324bc42b1999b723c0619eea6d; patch: 6.12.97; patch: 0; patch: 6.18.40; patch: 7.2; 1085b8276bb4239daa7008f0dcd5c973e4bd690f <73851a7c43dfa52d2ed9415889b33daf85da0ed9; 1085b8276bb4239daa7008f0dcd5c973e4bd690f <493333f167926c7adab8e7563e21ad71d8af84fa; 1085b8276bb4239daa7008f0dcd5c973e4bd690f <934d1cd40e2893bf7a041b54f6afd1c008d7a21c
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.