In the Linux kernel, the following vulnerability has been resolved: mtd: spi-nor: swp: Improve locking user experience In the case of the first… (CVE-2026-72155)
A vulnerability in the Linux kernel's mtd spi-nor swp driver related to unlocking blocks on a device has been resolved. The issue caused failures when attempting to unlock only the first block(s) because of incorrect lock length calculations. The fix involves adjusting the unlock logic to correctly handle cases where unlocking from either side results in unlocking the entire device.
AI Analysis
Technical Summary
The vulnerability in the Linux kernel mtd spi-nor swp driver involved improper handling of unlocking operations when the first block or few blocks were locked. Specifically, if a user requested to unlock only the currently locked blocks, the operation failed due to incorrect conditions involving 'can_be_top' and 'can_be_bottom' flags and an erroneous calculation of 'lock_len'. The fix adds an extra condition in the unlock path to set 'lock_len' to zero when unlocking the entire device, ensuring correct behavior and improving the locking user experience.
Potential Impact
This issue could cause failures in unlocking specific blocks on spi-nor devices, potentially leading to user inconvenience or inability to unlock parts of the device as intended. There is no indication of security impact such as privilege escalation or code execution. No known exploits are reported in the wild.
Mitigation Recommendations
The vulnerability has been resolved in the Linux kernel. Users should update to a kernel version that includes this fix. Patch status is not explicitly stated; check the vendor or Linux kernel advisories for the exact fixed version and apply the update accordingly.
In the Linux kernel, the following vulnerability has been resolved: mtd: spi-nor: swp: Improve locking user experience In the case of the first… (CVE-2026-72155)
Description
A vulnerability in the Linux kernel's mtd spi-nor swp driver related to unlocking blocks on a device has been resolved. The issue caused failures when attempting to unlock only the first block(s) because of incorrect lock length calculations. The fix involves adjusting the unlock logic to correctly handle cases where unlocking from either side results in unlocking the entire device.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in the Linux kernel mtd spi-nor swp driver involved improper handling of unlocking operations when the first block or few blocks were locked. Specifically, if a user requested to unlock only the currently locked blocks, the operation failed due to incorrect conditions involving 'can_be_top' and 'can_be_bottom' flags and an erroneous calculation of 'lock_len'. The fix adds an extra condition in the unlock path to set 'lock_len' to zero when unlocking the entire device, ensuring correct behavior and improving the locking user experience.
Potential Impact
This issue could cause failures in unlocking specific blocks on spi-nor devices, potentially leading to user inconvenience or inability to unlock parts of the device as intended. There is no indication of security impact such as privilege escalation or code execution. No known exploits are reported in the wild.
Mitigation Recommendations
The vulnerability has been resolved in the Linux kernel. Users should update to a kernel version that includes this fix. Patch status is not explicitly stated; check the vendor or Linux kernel advisories for the exact fixed version and apply the update accordingly.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-4g3m-gr2j-r4mp
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-72155"]
- Ecosystems
- []
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a808b75bf8831d5394ff7d8
Added to database: 08/15/2026, 15:53:25 UTC
Last enriched: 08/15/2026, 16:54:45 UTC
Last updated: 08/15/2026, 21:21:07 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.