Improper control of a resource through its lifetime in Linux kernel - CVE-2026-43007
Published: May 2, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper state management in the qaic DBC deactivation handling when processing a device deactivation transaction after the owning user has exited. A local user can terminate the owning process and then request activation of a network to cause a denial of service.
The issue can leave the host out of sync with available DBCs, causing a subsequent user process to hang while waiting for the DBC to become unused.
How to mitigate CVE-2026-43007
Sources
- https://git.kernel.org/stable/c/08021f2d4a557d6491e3bcc288e96425f50aa3cf
- https://git.kernel.org/stable/c/2dd67966f39a2abf8ccb4865031c722e40e01b7f
- https://git.kernel.org/stable/c/2feec5ae5df785658924ab6bd91280dc3926507c
- https://git.kernel.org/stable/c/ee0180e77e6c8482644569632065411de844c515
- https://git.kernel.org/stable/c/f403094d9075d7c565a3d81002b781c325cb3c07