CVE intelligence
CVE-2026-72167
Vulnerability intelligence
Published Aug 15, 2026 Sources checked Oct 8, 2026
N/A CVSS not listed Score unavailable
What this means
Review the available evidence
CVE-2026-72167. It is not in the current CISA KEV record we collected. That does not prove exploitation has not occurred.
CISA KEV Not listed Based on the latest collected catalog
EPSS 0.2% Estimated 30-day exploitation probability
Ransomware use Not marked CISA KEV ransomware field
Threat actors 0 Source-linked actor relationships
Overview
What is CVE-2026-72167?
In the Linux kernel, the following vulnerability has been resolved:
mtd: rawnand: pl353: fix probe resource allocation
During probe(), the devm_ioremap() is called with the parent device instead of the current one. So when the module is unloaded, the register area isn't released.
Target the pl35x device in the devm_ioremap() instead of its parent.
Source: NVD
Sources Check the original records SecurityAlert keeps CVSS, KEV, EPSS, vendor guidance, and actor links separate so you can see where each fact came from.