Status: NEW | Advisory ID: CVE-2026-72397
| CVE | CVE-2026-72397 |
| CVSS Score / Version | 7.1 (High) / CVSS v3.1 |
| Updated | 2026-08-17 |
| CVSS Vector | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H |
| CVSS Prose | attack vector is local; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is none; integrity impact is high; availability impact is high. |
In the Linux kernel, the following vulnerability has been resolved:
hwmon: (pmbus/core) honor vrm_version in pmbus_data2reg_vid()
pmbus_data2reg_vid() hardcoded the VR11 encoding regardless of the
vrm_version configured by the driver, while pmbus_reg2data_vid()
already switched on it. Any driver that selects a non-VR11 VID mode
and exposes a regulator (or hwmon vout setter) sent dangerously
wrong codes to PMBUS_VOUT_COMMAND -- e.g. an nvidia195mv part asked
for 200 mV got the VR11 clamp to 500 mV encoded as 0xB2, which the
chip interprets as 1080 mV.
Mirror pmbus_reg2data_vid() so writes round-trip with reads. (NVD)
| Source | Reference |
|---|---|
| NVD | https://nvd.nist.gov/vuln/detail/CVE-2026-72397 |
| CVE | https://www.cve.org/CVERecord?id=CVE-2026-72397 |