In the Linux kernel, the following vulnerability has been resolved: ASoC: mediatek: mt8192: Check runtime resume during probe The MT8192 AFE probe… (CVE-2026-72260)
A vulnerability in the Linux kernel's ASoC mediatek mt8192 driver was resolved. The issue involved improper handling of runtime power management during the MT8192 AFE probe, where failures in runtime resume were not checked, potentially leading to incorrect power management state and resource leaks. The fix ensures proper checking of runtime resume results and correct handling of power management references.
AI Analysis
Technical Summary
The vulnerability in the Linux kernel's ASoC mediatek mt8192 driver arises because the MT8192 AFE probe temporarily enables runtime power management (PM) while reinitializing the regmap cache from hardware. It uses pm_runtime_get_sync() without verifying its return value. If the runtime resume fails, the probe continues without the device being accessible, and the PM usage count may be incorrectly incremented. Additionally, the failure path in regmap_reinit_cache() returns before dropping the temporary PM reference and clearing the pm_runtime_bypass_reg_ctl flag. The fix replaces pm_runtime_get_sync() with pm_runtime_resume_and_get() to prevent usage count leaks on resume failure and ensures the temporary bypass flag is cleared after dropping the probe PM reference regardless of regmap_reinit_cache() outcome.
Potential Impact
If exploited, this vulnerability could cause the device driver to operate with an incorrect power management state, potentially leading to resource leaks or improper device accessibility during initialization. However, no known exploits in the wild have been reported. The impact is limited to the affected driver and may affect device stability or power management correctness.
Mitigation Recommendations
A fix has been implemented in the Linux kernel to address this issue by properly checking runtime resume results and managing power management references correctly. Users should update to the fixed Linux kernel version containing this patch. Since this is a kernel-level fix, applying the official kernel update is the recommended remediation. Patch status is not explicitly stated here; check the vendor or Linux kernel advisory for the exact fixed version and update accordingly.
In the Linux kernel, the following vulnerability has been resolved: ASoC: mediatek: mt8192: Check runtime resume during probe The MT8192 AFE probe… (CVE-2026-72260)
Description
A vulnerability in the Linux kernel's ASoC mediatek mt8192 driver was resolved. The issue involved improper handling of runtime power management during the MT8192 AFE probe, where failures in runtime resume were not checked, potentially leading to incorrect power management state and resource leaks. The fix ensures proper checking of runtime resume results and correct handling of power management references.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in the Linux kernel's ASoC mediatek mt8192 driver arises because the MT8192 AFE probe temporarily enables runtime power management (PM) while reinitializing the regmap cache from hardware. It uses pm_runtime_get_sync() without verifying its return value. If the runtime resume fails, the probe continues without the device being accessible, and the PM usage count may be incorrectly incremented. Additionally, the failure path in regmap_reinit_cache() returns before dropping the temporary PM reference and clearing the pm_runtime_bypass_reg_ctl flag. The fix replaces pm_runtime_get_sync() with pm_runtime_resume_and_get() to prevent usage count leaks on resume failure and ensures the temporary bypass flag is cleared after dropping the probe PM reference regardless of regmap_reinit_cache() outcome.
Potential Impact
If exploited, this vulnerability could cause the device driver to operate with an incorrect power management state, potentially leading to resource leaks or improper device accessibility during initialization. However, no known exploits in the wild have been reported. The impact is limited to the affected driver and may affect device stability or power management correctness.
Mitigation Recommendations
A fix has been implemented in the Linux kernel to address this issue by properly checking runtime resume results and managing power management references correctly. Users should update to the fixed Linux kernel version containing this patch. Since this is a kernel-level fix, applying the official kernel update is the recommended remediation. Patch status is not explicitly stated here; check the vendor or Linux kernel advisory for the exact fixed version and update accordingly.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-g833-2rhh-96rv
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-72260"]
- Ecosystems
- []
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a808b73bf8831d5394fd9c3
Added to database: 08/15/2026, 15:53:23 UTC
Last enriched: 08/15/2026, 16:44:58 UTC
Last updated: 08/16/2026, 00:41:15 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.