CVE-2026-72140
Last modified
CVE-2026-72140 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: i2c: mlxbf: Fix use-after-free in mlxbf_i2c_init_resource() If devm_platform_get_and_ioremap_resource() returns an error, mlxbf_i2c_init_resource() frees tmp_res before reading tmp_res->io to get the error code. This results in a use-after-free. Save the error code before freeing tmp_res.. EPSS estimates a 0.21% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: i2c: mlxbf: Fix use-after-free in mlxbf_i2c_init_resource() If devm_platform_get_and_ioremap_resource() returns an error, mlxbf_i2c_init_resource() frees tmp_res before reading tmp_res->io to get the error code. This results in a use-after-free. Save the error code before freeing tmp_res.
Metrics
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= b5b5b32081cd206baa6e58cca7f112d9723785d6, < 6a108c9f5a81bb7b29dbb1398be0089655b6bfd2; >= b5b5b32081cd206baa6e58cca7f112d9723785d6, < c4d9b6a0c9645366d9e4af8a6ac8347bd4c841aa; >= b5b5b32081cd206baa6e58cca7f112d9723785d6, < b398cbbbb9dd76210682a8c9aabd34c5168800b9; >= b5b5b32081cd206baa6e58cca7f112d9723785d6, < 5290a52533e09c38374963f4bb0b35121fe555c7; >= b5b5b32081cd206baa6e58cca7f112d9723785d6, < ce960a1b2caa4ad08291f28d8bcf17ad5a864e54; >= b5b5b32081cd206baa6e58cca7f112d9723785d6, < e6a395a71f4652261d09b572a03c96052662a056; >= b5b5b32081cd206baa6e58cca7f112d9723785d6, < fb267770bf822064f510c9b46743f533d8fa8a5f; >= b5b5b32081cd206baa6e58cca7f112d9723785d6, < 71356737a7a55c76fee847563e3d33f8e6dc6b6d |
| Linux | Linux | 5.10 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-72140?
How severe is CVE-2026-72140?
How do I fix CVE-2026-72140?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-72135In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-72136In the Linux kernel, the following vulnerability has been re…8.8
- CVE-2026-72137In the Linux kernel, the following vulnerability has been re…9.8
- CVE-2026-72138In the Linux kernel, the following vulnerability has been re…
- CVE-2026-72139In the Linux kernel, the following vulnerability has been re…9.8
- CVE-2026-7214A vulnerability was identified in eghuzefa engineer-your-dat…7.3
- CVE-2026-72141In the Linux kernel, the following vulnerability has been re…7.5
- CVE-2026-72142In the Linux kernel, the following vulnerability has been re…
- CVE-2026-72143In the Linux kernel, the following vulnerability has been re…7.1
- CVE-2026-72144In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-72145In the Linux kernel, the following vulnerability has been re…
- CVE-2026-72146In the Linux kernel, the following vulnerability has been re…8.4
Are you affected by CVE-2026-72140?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
