CVE-2026-72067

Source
https://cve.org/CVERecord?id=CVE-2026-72067
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72067.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-72067
Downstream
Published
2026-08-15T05:52:20.268Z
Modified
2026-08-18T03:56:19.592217552Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
cpu: hotplug: Preserve per instance callback errors
Details

In the Linux kernel, the following vulnerability has been resolved:

cpu: hotplug: Preserve per instance callback errors

cpuhpinvokecallback() unwinds earlier callbacks for the same hotplug state when one instance fails. The rollback path currently reuses ret, so a successful rollback can hide the original error and make the failed transition look successful.

Keep the rollback result separate from the original error.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72067.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
724a86881d03ee5794148e65142e24ed3621be66
Fixed
fe9c8d641f6991614d1229a3ffd3e33b879bba9c
Fixed
ef39758637cc5b603fb05b625c45a98aa306e338
Fixed
95232281512b15338549171ed9a2acf21f946ffb
Fixed
7a68257b90d8a9b6d605abc99469ded45ecba63b
Fixed
77d4fa8a3ea1c3e8b996ac35e59aee9e77389905
Fixed
f77117530fc3f5932ffb107182a6dd34006be9b6
Fixed
9f7dc355f62c011e4afe8286cf71130d4bfb9d80
Fixed
673db10729fb121ea1b16fe57791a0cb9eac1eb5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72067.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.14.0
Fixed
5.10.261
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.212
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.178
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.145
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.97
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.40
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72067.json"