Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

In the Linux kernel, the following vulnerability has been resolved: cpu/hotplug: Fix NULL kobject warning in cpuhp_smt_enable() On arm64, when… (CVE-2026-72016)

0
Medium
Published: 08/15/2026 (08/15/2026, 06:32:09 UTC)
Source: GCVE Database

Description

A vulnerability in the Linux kernel on arm64 platforms related to CPU hotplug handling has been resolved. The issue occurs when booting with a maxcpus value greater than the number of present CPUs, causing some CPUs to be marked as present but not registered. This leads to a NULL kobject warning during sysfs group creation, potentially causing instability or kernel warnings. The fix ensures only physically available or explicitly enabled CPUs are marked present, aligning CPU hotplug logic with actual hardware state.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/15/2026, 17:09:07 UTC

Technical Analysis

The Linux kernel vulnerability CVE-2026-72016 affects arm64 architectures when booting with a maxcpus parameter greater than the number of physically present CPUs (e.g., QEMU configurations with more maxcpus than CPUs). This causes CPUs to be marked as present without being registered, resulting in uninitialized per-CPU device objects. When cpuhp_smt_enable() iterates over these CPUs and calls _cpu_up(), sysfs_create_group() is invoked with a NULL kobject, triggering kernel warnings. The root cause is that ACPI SMP initialization sets all enumerated CPUs as present regardless of their MADT status, causing SMT hotplug control issues. The fix involves checking the ACPI_MADT_ENABLED flag before marking CPUs present, properly managing the present mask during CPU mapping/unmapping, and updating documentation to reflect the corrected behavior.

Potential Impact

This vulnerability causes kernel warnings due to NULL kobject dereferences during CPU hotplug operations on arm64 systems booted with certain maxcpus configurations. While no direct exploit or code execution is reported, the issue can lead to system instability or unexpected behavior in CPU hotplug and SMT control logic. It affects kernel reliability and correctness in managing CPU states but does not indicate privilege escalation or data compromise.

Mitigation Recommendations

A fix has been implemented in the Linux kernel to address this issue by properly managing the present CPU mask and checking ACPI flags during SMP initialization on arm64. Users should update to the fixed kernel version once available. Patch status is not explicitly provided in the input; therefore, check the official Linux kernel vendor advisories or distribution security updates for the relevant patch. No additional mitigation is required beyond applying the official fix.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-jpp3-3v9r-hwrp
Osv Schema Version
1.4.0
Aliases
["CVE-2026-72016"]
Ecosystems
[]
Database Specific Severity
null
Cvss Version
null

Threat ID: 6a808b78bf8831d53950217a

Added to database: 08/15/2026, 15:53:28 UTC

Last enriched: 08/15/2026, 17:09:07 UTC

Last updated: 08/15/2026, 18:28:34 UTC

Views: 4

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses