Improper locking in Linux kernel - CVE-2026-43423
Published: May 8, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper locking in ncm_set_alt in the f_ncm USB gadget function when handling USB configuration changes. A local user can trigger the vulnerable code path to cause a denial of service.
The issue results in a kernel bug caused by calling a sleeping function from an invalid atomic context.