Improper synchronization in Linux kernel - CVE-2026-43170
Published: May 7, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper execution in atomic context in dwc3_gadget_vbus_draw() when invoking power-supply-core APIs. A local user can trigger USB gadget operations to cause a denial of service.
The issue can lead to a kernel panic because some PMIC operations may sleep.
How to mitigate CVE-2026-43170
Sources
- https://git.kernel.org/stable/c/2333653ef854c2cc124077f71a8526f03bf6e06a
- https://git.kernel.org/stable/c/54aaa3b387c2f580a99dc86a9cc2eb6dfaf599a7
- https://git.kernel.org/stable/c/74a231e3d99d310497ab0ccb359539a6063b316a
- https://git.kernel.org/stable/c/76c1123ffccfaba95cf4ecc2a50f95504a522424
- https://git.kernel.org/stable/c/a7a80c25b65112768eeba58a7af129d3c52a6d90