CVE-2026-72167

Source
https://cve.org/CVERecord?id=CVE-2026-72167
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72167.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-72167
Downstream
Published
2026-08-15T05:53:34.123Z
Modified
2026-08-18T03:30:56.050814770Z
Summary
mtd: rawnand: pl353: fix probe resource allocation
Details

In the Linux kernel, the following vulnerability has been resolved:

mtd: rawnand: pl353: fix probe resource allocation

During probe(), the devm_ioremap() is called with the parent device instead of the current one. So when the module is unloaded, the register area isn't released.

Target the pl35x device in the devm_ioremap() instead of its parent.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72167.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
08d8c62164a322eb923034acacf25246b775593a
Fixed
593201a8f43864cb7e25197095f6716a589584fd
Fixed
862c6738833b5b01c801cc47023272f5eaa9a7b2
Fixed
afddc648403511b6d2e978e73686c77549bc72b3
Fixed
c4c9180b3b23f82e1ec429350b420c45c5b5100e
Fixed
ace3a0c839f3bfe1779c6708e7709c824b96dc2f
Fixed
3c44f6c62f652d3ac9d03beb8a199e6388256cdd
Fixed
19ed11aee966d91beebdef9d32ce926474872f79

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72167.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.14.0
Fixed
5.15.212
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.178
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.145
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.97
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.40
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72167.json"