Answer in brief
CVE-2026-72005 records a Unknown severity vulnerability in wifi: rt2x00: avoid full teardown before work setup in probe. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
Answer in brief
CVE-2026-72005 records a Unknown severity vulnerability in wifi: rt2x00: avoid full teardown before work setup in probe. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=0439f5367c8d8bb2ebaca8d7329f51f3148b2fb2 <8b58d1f1356df6a7d2de3f55bb665b18b04ffda0 || >=0439f5367c8d8bb2ebaca8d7329f51f3148b2fb2 <59afe6148927395cf86f9429900e029a48b1d42b || >=0439f5367c8d8bb2ebaca8d7329f51f3148b2fb2 <3c0427d719bddb33caf18ff4ffb77cb47de7eb00 || >=0439f5367c8d8bb2ebaca8d7329f51f3148b2fb2 <eb7474d0253bb2de4793e1d3ce833e8564bbe732 || >=0439f5367c8d8bb2ebaca8d7329f51f3148b2fb2 <66bd9b1a72de7c2f5141b02d796048aafaed8a49 || >=0439f5367c8d8bb2ebaca8d7329f51f3148b2fb2 <816559409e340acaa5c9d868291dab30d8c80263 || >=0439f5367c8d8bb2ebaca8d7329f51f3148b2fb2 <56994852d704535ea354a4627ca667b1b4fa0deb || >=0439f5367c8d8bb2ebaca8d7329f51f3148b2fb2 <536fb3d739d75a03cb318c0c6fe799425cfea501 | 8b58d1f1356df6a7d2de3f55bb665b18b04ffda0, 59afe6148927395cf86f9429900e029a48b1d42b, 3c0427d719bddb33caf18ff4ffb77cb47de7eb00, eb7474d0253bb2de4793e1d3ce833e8564bbe732, 66bd9b1a72de7c2f5141b02d796048aafaed8a49, 816559409e340acaa5c9d868291dab30d8c80263, 56994852d704535ea354a4627ca667b1b4fa0deb, 536fb3d739d75a03cb318c0c6fe799425cfea501 |
| Linux/Linuxgeneric | 2.6.39 | Not reported |
Published upstream
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 15, 2026
In the Linux kernel, the following vulnerability has been resolved: wifi: rt2x00: avoid full teardown before work setup in probe rt2x00lib_probe_dev() uses the full rt2x00lib_remove_dev() teardown for all probe failures. However, drv_data allocation and workqueue allocation can fail before intf_work, autowakeup_work and sleep_work have been initialized. Do not enter the full remove path until the probe has reached the point where those work items are set up. Return directly for drv_data allocation failure, and use a small early cleanup path for workqueue allocation failure. This issue was found by our static analysis tool and then confirmed by manual review of rt2x00lib_probe_dev() and rt2x00lib_remove_dev(). The early probe exits should not call a common teardown path that assumes the later work setup has already completed. A QEMU PoC forced alloc_ordered_workqueue() to fail before the work initializers are reached. The resulting fail path entered rt2x00lib_remove_dev(), and DEBUG_OBJECTS reported invalid work drains with rt2x00lib_probe_dev() and rt2x00lib_remove_dev() in the stack.
Quoted source text, attributed separately from HOL analysis.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=0439f5367c8d8bb2ebaca8d7329f51f3148b2fb2 <8b58d1f1356df6a7d2de3f55bb665b18b04ffda0 || >=0439f5367c8d8bb2ebaca8d7329f51f3148b2fb2 <59afe6148927395cf86f9429900e029a48b1d42b || >=0439f5367c8d8bb2ebaca8d7329f51f3148b2fb2 <3c0427d719bddb33caf18ff4ffb77cb47de7eb00 || >=0439f5367c8d8bb2ebaca8d7329f51f3148b2fb2 <eb7474d0253bb2de4793e1d3ce833e8564bbe732 || >=0439f5367c8d8bb2ebaca8d7329f51f3148b2fb2 <66bd9b1a72de7c2f5141b02d796048aafaed8a49 || >=0439f5367c8d8bb2ebaca8d7329f51f3148b2fb2 <816559409e340acaa5c9d868291dab30d8c80263 || >=0439f5367c8d8bb2ebaca8d7329f51f3148b2fb2 <56994852d704535ea354a4627ca667b1b4fa0deb || >=0439f5367c8d8bb2ebaca8d7329f51f3148b2fb2 <536fb3d739d75a03cb318c0c6fe799425cfea501 | 8b58d1f1356df6a7d2de3f55bb665b18b04ffda0, 59afe6148927395cf86f9429900e029a48b1d42b, 3c0427d719bddb33caf18ff4ffb77cb47de7eb00, eb7474d0253bb2de4793e1d3ce833e8564bbe732, 66bd9b1a72de7c2f5141b02d796048aafaed8a49, 816559409e340acaa5c9d868291dab30d8c80263, 56994852d704535ea354a4627ca667b1b4fa0deb, 536fb3d739d75a03cb318c0c6fe799425cfea501 |
| Linux/Linuxgeneric | 2.6.39 | Not reported |
Published upstream
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 15, 2026
In the Linux kernel, the following vulnerability has been resolved: wifi: rt2x00: avoid full teardown before work setup in probe rt2x00lib_probe_dev() uses the full rt2x00lib_remove_dev() teardown for all probe failures. However, drv_data allocation and workqueue allocation can fail before intf_work, autowakeup_work and sleep_work have been initialized. Do not enter the full remove path until the probe has reached the point where those work items are set up. Return directly for drv_data allocation failure, and use a small early cleanup path for workqueue allocation failure. This issue was found by our static analysis tool and then confirmed by manual review of rt2x00lib_probe_dev() and rt2x00lib_remove_dev(). The early probe exits should not call a common teardown path that assumes the later work setup has already completed. A QEMU PoC forced alloc_ordered_workqueue() to fail before the work initializers are reached. The resulting fail path entered rt2x00lib_remove_dev(), and DEBUG_OBJECTS reported invalid work drains with rt2x00lib_probe_dev() and rt2x00lib_remove_dev() in the stack.
Quoted source text, attributed separately from HOL analysis.