CVE-2026-72394

Source
https://cve.org/CVERecord?id=CVE-2026-72394
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72394.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-72394
Downstream
Published
2026-08-15T05:56:21.707Z
Modified
2026-08-18T03:31:23.426150097Z
Summary
hwmon: (aspeed-g6-pwm-tach) Guard fan RPM calculation against divide-by-zero
Details

In the Linux kernel, the following vulnerability has been resolved:

hwmon: (aspeed-g6-pwm-tach) Guard fan RPM calculation against divide-by-zero

Sashiko reports:

In the aspeed-g6-pwm-tacho driver, the aspeedtachvaltorpm() function calculates the fan RPM using the tachometer value. However, it does not check if the tachometer value is zero before performing the division.

If the hardware reports a tachometer value of 0 (which can happen due to an extremely fast pulse, a stuck edge, or a hardware glitch), the calculated tachdiv evaluates to 0. The subsequent call to dodiv() with tach_div as the divisor triggers a divide-by-zero exception, leading to a kernel panic.

Check the divisor against zero to fix the problem.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72394.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
7e1449cd15d1096157d1a9923b82e37602fb7eb0
Fixed
a3f98bd397398e2d4a7f98e006b5aaf4d54ebdf3
Fixed
898ca04b096b9e4640300eab91468c826a1ec92b
Fixed
fb8a5afe6f1f8aa7f19c6dda23d277dd6ae5d9e1
Fixed
fe87b8dc67f1b2c64e76a66e78468c533d3c44ca

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72394.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.9.0
Fixed
6.12.97
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.40
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72394.json"