{"apiVersion":"1.0","identifier":"CVE-2026-72395","description":"In the Linux kernel, the following vulnerability has been resolved: hwmon: (pmbus) Fix passing events to regulator core Sashiko reports: Commit 754bd2b4a084 (-hwmon: (pmbus/core) Protect regulator operations with mutex-) introduced a worker to batch regulator events over time using atomic_or(). The delayed worker then passes the combined bitmask unmodified to regulator_notifier_call_chain(). The core regulator subsystem-s regulator_handle_critical() function evaluates the event parameter using a strict switch statement. If multiple distinct faults occur before the worker runs (e.g., REGULATOR_EVENT_UNDER_VOLTAGE | REGULATOR_EVENT_OVER_CURRENT), the combined bitmask fails to match any case. This leaves the reason as NULL and completely bypasses the critical hw_protection_trigger(). Fix the problem by passing events bit by bit to the regulator event handler.","publishedAt":"2026-08-15T06:22:13","lastModifiedAt":"2026-08-17T06:19:05","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-72395","cvssScore":7.1,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H","epssProbability":0.00169,"riskScore":0.72,"affectedProduct":"linux","affectedVersions":"unknown","vulnerabilityType":"Kernel","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-72395","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-72395","en":"https://www.redsauce.net/en/cves/CVE-2026-72395","fr":"https://www.redsauce.net/fr/cves/CVE-2026-72395","pt":"https://www.redsauce.net/pt/cves/CVE-2026-72395","de":"https://www.redsauce.net/de/cves/CVE-2026-72395","sk":"https://www.redsauce.net/sk/cves/CVE-2026-72395","el":"https://www.redsauce.net/el/cves/CVE-2026-72395"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-72395"}}