Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2026-72008

Published Aug 15, 2026 EPSS 0.19% (9th pctl)

Overview

CVE-2026-72008 is a known-severity vulnerability. It was published on August 15, 2026.

Technical Description

In the Linux kernel, the following vulnerability has been resolved:

pmdomain: mediatek: Fix possible nullptr KP in HWV cleanup/on-check

Should probe fail for HW_VOTER type power domains, this driver was

unconditionally trying to perform cleanup for DIRECT_CTL domains,

but only after checking if the target domain is powered on... with

the DIRECT_CTL scpsys_domain_is_on() code again.

And there's more: the scpsys_domain_is_on() function is also being

unconditionally used in the probe path, for any power domain that

has flag MTK_SCPD_KEEP_DEFAULT_OFF!

This bug was never experienced by anyone because the HWV domains

never failed probe, and because none of those is declared with the

aforementioned flag - but it's still something critical.

In order to fix this, add a check for MTCMOS Type and, based on

that, call the correct functions for an "is on" check, and also

do the same for the cleanup path, calling the correct functions

for the "power off" action.

For the latter, since there's a

Remediation

Check the references section for vendor advisories, patches, and mitigation guidance. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Frequently Asked Questions

What is CVE-2026-72008?

CVE-2026-72008 is a known-severity vulnerability. It was published on August 15, 2026.

How severe is CVE-2026-72008?

CVSS score information is not yet available for this vulnerability. Check back as the CVE record is updated by NVD analysts.

How do I fix or remediate CVE-2026-72008?

Check the references section for vendor advisories, patches, and mitigation guidance. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2026-72008?

CyberStrike's AI-powered security agents can automatically detect CVE-2026-72008 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.