CVE-2026-72152
CVE CVE-2026-72152EUVD EUVD-2026-58910Published 2026-08-15T05:53:22.000ZLast changed 2026-08-17T05:09:11.000Z
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: tpm: tpm_tis_spi: Use wait_woken() in wait_for_tmp_stat() wait_event_interruptible_timeout() evaluates its condition after setting the current task state to TASK_INTERRUPTIBLE. With CONFIG_DEBUG_ATOMIC_SLEEP this triggers a warning when the IRQ wait path is used: tpm_tis_status() tpm_tis_spi_read_bytes() tpm_tis_spi_transfer_full() spi_bus_lock() mutex_lock() Address this with the following measures: 1. Call wait_tpm_stat_cond() only while tasking is running. 2. Use wait_woken() to wait for changes.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux 1a339b658d9dbe1471f67b78237cf8fa08bbbeb5 <bb63a0530e8e6de3aaf29cd5ba487db2490128ef; patch: 6.18.40; patch: 0; patch: 6.12.97; 1a339b658d9dbe1471f67b78237cf8fa08bbbeb5 <4bb3e1bc142dc9c3240ceed1b3ab031aa9cb1723; d229e7ecc0cb29996688f0fa98c5eb6128b81e3a; 4.19; cd4ae0b05126cc9461a2e50ccb745e5583cc91e2; patch: 7.1.5; 4.14.71 <4.15; 1a339b658d9dbe1471f67b78237cf8fa08bbbeb5 <6b068a97958aa00a901a9b5083d74114b21f7b66; patch: 7.2; 4.9.128 <4.10; cf503dbe5c22c6ab9797e1cf864a11597d711c3a; 1a339b658d9dbe1471f67b78237cf8fa08bbbeb5 <ba33b4f9d3423accd2c91a0b0b0680cd589922f2; patch: 6.1.178; 4.18.9 <4.19; 1a339b658d9dbe1471f67b78237cf8fa08bbbeb5 <c9acbe38797bc1aa3c22a1ab72452e210af6e0ff; patch: 6.6.145; 1a339b658d9dbe1471f67b78237cf8fa08bbbeb5 <c0c9cfb3b75def8bf200a2d4db09015806acfeaf
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.