Answer in brief
CVE-2026-72482 records a Unknown severity vulnerability in gpib: fix double decrement of descriptor_busy in command_ioctl(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=cae26eff1b56d78bed7873cf3e60a2b1bdd4da6c <fdee9f207a48ce204ec6cfceaa1459d2473600a5 || >=d1857f8296dceb75d00ab857fc3c61bc00c7f5c6 <8b5f1d295dda8677e4545ce340053fcfa8b634c7 || >=d1857f8296dceb75d00ab857fc3c61bc00c7f5c6 <c4faab452b3c1ada003d49c477609dd80523b9bf || 28c75dd143ead62e0dfac564c79d251e21d5d74b || >=6.18.22 <6.18.40 || >=6.19.12 <6.20 | fdee9f207a48ce204ec6cfceaa1459d2473600a5, 8b5f1d295dda8677e4545ce340053fcfa8b634c7, c4faab452b3c1ada003d49c477609dd80523b9bf, 6.18.40, 6.20 |
| Linux/Linuxgeneric | 7.0 | Not reported |
Published upstream
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 15, 2026
In the Linux kernel, the following vulnerability has been resolved: gpib: fix double decrement of descriptor_busy in command_ioctl() commit d1857f8296dc ("gpib: fix use-after-free in IO ioctl handlers") introduced a descriptor_busy reference counter to pin struct gpib_descriptor across IO ioctl operations. In command_ioctl(), the error path inside the loop decrements descriptor_busy and breaks, but execution then falls through to the unconditional decrement after the loop, underflowing the counter to -1. This re-enables the use-after-free that the original fix was meant to prevent: a concurrent close_dev_ioctl() sees descriptor_busy == 0 on an actively-used descriptor and frees it. Remove the early decrement from the error path. The post-loop decrement already handles all exit paths, matching the correct pattern used in read_ioctl() and write_ioctl().
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2026-72482 records a Unknown severity vulnerability in gpib: fix double decrement of descriptor_busy in command_ioctl(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=cae26eff1b56d78bed7873cf3e60a2b1bdd4da6c <fdee9f207a48ce204ec6cfceaa1459d2473600a5 || >=d1857f8296dceb75d00ab857fc3c61bc00c7f5c6 <8b5f1d295dda8677e4545ce340053fcfa8b634c7 || >=d1857f8296dceb75d00ab857fc3c61bc00c7f5c6 <c4faab452b3c1ada003d49c477609dd80523b9bf || 28c75dd143ead62e0dfac564c79d251e21d5d74b || >=6.18.22 <6.18.40 || >=6.19.12 <6.20 | fdee9f207a48ce204ec6cfceaa1459d2473600a5, 8b5f1d295dda8677e4545ce340053fcfa8b634c7, c4faab452b3c1ada003d49c477609dd80523b9bf, 6.18.40, 6.20 |
| Linux/Linuxgeneric | 7.0 | Not reported |
Published upstream
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 15, 2026
In the Linux kernel, the following vulnerability has been resolved: gpib: fix double decrement of descriptor_busy in command_ioctl() commit d1857f8296dc ("gpib: fix use-after-free in IO ioctl handlers") introduced a descriptor_busy reference counter to pin struct gpib_descriptor across IO ioctl operations. In command_ioctl(), the error path inside the loop decrements descriptor_busy and breaks, but execution then falls through to the unconditional decrement after the loop, underflowing the counter to -1. This re-enables the use-after-free that the original fix was meant to prevent: a concurrent close_dev_ioctl() sees descriptor_busy == 0 on an actively-used descriptor and frees it. Remove the early decrement from the error path. The post-loop decrement already handles all exit paths, matching the correct pattern used in read_ioctl() and write_ioctl().
Quoted source text, attributed separately from HOL analysis.