CVE-2026-80930Medium· 5.5▾ SunlitA flaw was found in the Linux kernel's TPM I2C Nuvoton driver. The `i2c_nuvoton_wait_for_stat()` function enables an interrupt (IRQ) but fails to disable it if the wait operation times out or is interrupted. This oversight can lead to an u…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 30.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.2%
— → 4.1
none → medium
— → 4.1
none → medium
Last analysed / modified upstream
— → 5.5
none → medium
0.2% → 0.2%
A flaw was found in the Linux kernel's TPM I2C Nuvoton driver. The i2c_nuvoton_wait_for_stat() function enables an interrupt (IRQ) but fails to disable it if the wait operation times out or is interrupted. This oversight can lead to an unbalanced IRQ state, potentially causing system instability or resource exhaustion, which could result in a Denial of Service (DoS).
kernel: tpm: tpm_i2c_nuvoton: disable IRQ on wait timeout — rated Low by Red Hat. Released 2026-09-11, updated 2026-09-14.
Affected:
No fix planned:
Not affected:
Fix deferred
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-80948Medium· 5.5kernel: wifi: iwlwifi: dvm: fix memory leak in iwl_op_mode_dvm_start() (CVE-2026-80948)
CVE-2026-80939Medium· 5.5kernel: wifi: rtw89: pci: add .shutdown callback to stop rfkill polling on reboot (CVE-2026-80939)
CVE-2026-80941Medium· 5.5kernel: wifi: rtw88: Fix potential memory leak in rtw_txq_push_skb() (CVE-2026-80941)
CVE-2026-80949Medium· 5.5kernel: wifi: brcmfmac: Fix memory leak in brcmf_sdio_read_control() (CVE-2026-80949)
CVE-2026-80987Medium· 5.5kernel: NTB: ntb_transport: Reject oversized TX buffers (CVE-2026-80987)
CVE-2026-80990Medium· 5.5kernel: net: thunderbolt: Release the Rx HopID that was handed out on mismatch (CVE-2026-80990)