← Back to CVE intelligence
CVE intelligence

CVE-2026-72133

Vulnerability intelligence

Published Aug 15, 2026Sources checked Oct 8, 2026
8.4HIGHCVSS out of 10
What this means

Review the available evidence

CVE-2026-72133 and is rated High severity with a CVSS score of 8.4. It is not in the current CISA KEV record we collected. That does not prove exploitation has not occurred.

CISA KEVNot listedBased on the latest collected catalog
EPSS0.2%Estimated 30-day exploitation probability
Ransomware useNot markedCISA KEV ransomware field
Threat actors0Source-linked actor relationships
Overview

What is CVE-2026-72133?

In the Linux kernel, the following vulnerability has been resolved:

spi: uniphier: Fix completion initialization order before devm_request_irq()

The driver calls devm_request_irq() before initializing the completion used by the interrupt handler. Because the interrupt may occur immediately after devm_request_irq(), the handler may execute before init_completion().

This may result in calling complete() on an uninitialized completion, causing undefined behavior. This has been observed with KASAN.

Fix this by initializing the completion before registering the IRQ.

Source: NVD