Improper control of a resource through its lifetime in Linux kernel - CVE-2026-43229
Published: May 7, 2026
Linux kernel
Linux Foundation
Description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper shutdown sequence in wave5 driver device removal handling when unregistering and removing the device during polling mode. A local user can trigger encoding operations and device removal to cause a denial of service.
The issue occurs because an hrtimer can continue queueing worker activity that reads hardware registers after the hardware has been powered down, leading to a bus error and kernel panic.