CVE-2026-72394
hwmon: (aspeed-g6-pwm-tach) Guard fan RPM calculation against divide-by-zero
Description
In the Linux kernel, the following vulnerability has been resolved: hwmon: (aspeed-g6-pwm-tach) Guard fan RPM calculation against divide-by-zero Sashiko reports: In the aspeed-g6-pwm-tacho driver, the aspeed_tach_val_to_rpm() function calculates the fan RPM using the tachometer value. However, it does not check if the tachometer value is zero before performing the division. If the hardware reports a tachometer value of 0 (which can happen due to an extremely fast pulse, a stuck edge, or a hardware glitch), the calculated tach_div evaluates to 0. The subsequent call to do_div() with tach_div as the divisor triggers a divide-by-zero exception, leading to a kernel panic. Check the divisor against zero to fix the problem.
INFO
Published Date :
Aug. 15, 2026, 6:22 a.m.
Last Modified :
Aug. 17, 2026, 6:19 a.m.
Remotely Exploit :
No
Source :
416baaa9-dc9f-4396-8d5f-8c081fb06d67
Solution
- Check divisor for zero before division.
- Update the Linux kernel.
- Apply vendor-provided patches.
References to Advisories, Solutions, and Tools
Here, you will find a curated list of external links that provide in-depth
information, practical solutions, and valuable tools related to
CVE-2026-72394.
CWE - Common Weakness Enumeration
While CVE identifies
specific instances of vulnerabilities, CWE categorizes the common flaws or
weaknesses that can lead to vulnerabilities. CVE-2026-72394 is
associated with the following CWEs:
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Attack Pattern Enumeration and Classification
(CAPEC)
stores attack patterns, which are descriptions of the common attributes and
approaches employed by adversaries to exploit the CVE-2026-72394
weaknesses.
We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).
Results are limited to the first 15 repositories due to potential performance issues.
The following list is the news that have been mention
CVE-2026-72394 vulnerability anywhere in the article.
The following table lists the changes that have been made to the
CVE-2026-72394 vulnerability over time.
Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.
-
CVE Modified by 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Aug. 17, 2026
Action Type Old Value New Value Changed Affected [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '7e1449cd15d1096157d1a9923b82e37602fb7eb0', 'lessThan': 'a3f98bd397398e2d4a7f98e006b5aaf4d54ebdf3', 'versionType': 'git'}, {'status': 'affected', 'version': '7e1449cd15d1096157d1a9923b82e37602fb7eb0', 'lessThan': '898ca04b096b9e4640300eab91468c826a1ec92b', 'versionType': 'git'}, {'status': 'affected', 'version': '7e1449cd15d1096157d1a9923b82e37602fb7eb0', 'lessThan': 'fb8a5afe6f1f8aa7f19c6dda23d277dd6ae5d9e1', 'versionType': 'git'}, {'status': 'affected', 'version': '7e1449cd15d1096157d1a9923b82e37602fb7eb0', 'lessThan': 'fe87b8dc67f1b2c64e76a66e78468c533d3c44ca', 'versionType': 'git'}], 'programFiles': ['drivers/hwmon/aspeed-g6-pwm-tach.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '6.9'}, {'status': 'unaffected', 'version': '0', 'lessThan': '6.9', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '6.12.97', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.40', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.1.5', 'versionType': 'semver', 'lessThanOrEqual': '7.1.*'}, {'status': 'unaffected', 'version': '7.2-rc2', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['drivers/hwmon/aspeed-g6-pwm-tach.c'], 'defaultStatus': 'affected'}] [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '7e1449cd15d1096157d1a9923b82e37602fb7eb0', 'lessThan': 'a3f98bd397398e2d4a7f98e006b5aaf4d54ebdf3', 'versionType': 'git'}, {'status': 'affected', 'version': '7e1449cd15d1096157d1a9923b82e37602fb7eb0', 'lessThan': '898ca04b096b9e4640300eab91468c826a1ec92b', 'versionType': 'git'}, {'status': 'affected', 'version': '7e1449cd15d1096157d1a9923b82e37602fb7eb0', 'lessThan': 'fb8a5afe6f1f8aa7f19c6dda23d277dd6ae5d9e1', 'versionType': 'git'}, {'status': 'affected', 'version': '7e1449cd15d1096157d1a9923b82e37602fb7eb0', 'lessThan': 'fe87b8dc67f1b2c64e76a66e78468c533d3c44ca', 'versionType': 'git'}], 'programFiles': ['drivers/hwmon/aspeed-g6-pwm-tach.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '6.9'}, {'status': 'unaffected', 'version': '0', 'lessThan': '6.9', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '6.12.97', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.40', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.1.5', 'versionType': 'semver', 'lessThanOrEqual': '7.1.*'}, {'status': 'unaffected', 'version': '7.2', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['drivers/hwmon/aspeed-g6-pwm-tach.c'], 'defaultStatus': 'affected'}] -
New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Aug. 15, 2026
Action Type Old Value New Value Added Affected [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '7e1449cd15d1096157d1a9923b82e37602fb7eb0', 'lessThan': 'a3f98bd397398e2d4a7f98e006b5aaf4d54ebdf3', 'versionType': 'git'}, {'status': 'affected', 'version': '7e1449cd15d1096157d1a9923b82e37602fb7eb0', 'lessThan': '898ca04b096b9e4640300eab91468c826a1ec92b', 'versionType': 'git'}, {'status': 'affected', 'version': '7e1449cd15d1096157d1a9923b82e37602fb7eb0', 'lessThan': 'fb8a5afe6f1f8aa7f19c6dda23d277dd6ae5d9e1', 'versionType': 'git'}, {'status': 'affected', 'version': '7e1449cd15d1096157d1a9923b82e37602fb7eb0', 'lessThan': 'fe87b8dc67f1b2c64e76a66e78468c533d3c44ca', 'versionType': 'git'}], 'programFiles': ['drivers/hwmon/aspeed-g6-pwm-tach.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '6.9'}, {'status': 'unaffected', 'version': '0', 'lessThan': '6.9', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '6.12.97', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.40', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.1.5', 'versionType': 'semver', 'lessThanOrEqual': '7.1.*'}, {'status': 'unaffected', 'version': '7.2-rc2', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['drivers/hwmon/aspeed-g6-pwm-tach.c'], 'defaultStatus': 'affected'}] Added Description In the Linux kernel, the following vulnerability has been resolved: hwmon: (aspeed-g6-pwm-tach) Guard fan RPM calculation against divide-by-zero Sashiko reports: In the aspeed-g6-pwm-tacho driver, the aspeed_tach_val_to_rpm() function calculates the fan RPM using the tachometer value. However, it does not check if the tachometer value is zero before performing the division. If the hardware reports a tachometer value of 0 (which can happen due to an extremely fast pulse, a stuck edge, or a hardware glitch), the calculated tach_div evaluates to 0. The subsequent call to do_div() with tach_div as the divisor triggers a divide-by-zero exception, leading to a kernel panic. Check the divisor against zero to fix the problem. Added Reference https://git.kernel.org/stable/c/898ca04b096b9e4640300eab91468c826a1ec92b Added Reference https://git.kernel.org/stable/c/a3f98bd397398e2d4a7f98e006b5aaf4d54ebdf3 Added Reference https://git.kernel.org/stable/c/fb8a5afe6f1f8aa7f19c6dda23d277dd6ae5d9e1 Added Reference https://git.kernel.org/stable/c/fe87b8dc67f1b2c64e76a66e78468c533d3c44ca