Improper control of a resource through its lifetime in Linux kernel - CVE-2026-43352
Published: May 9, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper state management in the DMA ring abort handling logic in the mipi-i3c-hci driver when processing DMA dequeue operations. A local user can trigger ring abort handling in an invalid ring state to cause a denial of service.
The issue can occur when the ring is already stopped, and the abort sequence may reset hardware ring pointers and disrupt controller state.
Affected software
Anolis OS
Ubuntu
bpftool
kernel
kernel-debug
kernel-debug-devel
kernel-devel
kernel-headers
kernel-tools
kernel-tools-libs
kernel-tools-libs-devel
perf
python3-perf
linux-nvidia-tegra (Ubuntu package)
How to mitigate CVE-2026-43352
bpftool - update to 6.6.102-7
kernel - update to 6.6.102-7
kernel-debug - update to 6.6.102-7
kernel-debug-devel - update to 6.6.102-7
kernel-devel - update to 6.6.102-7
kernel-headers - update to 6.6.102-7
kernel-tools - update to 6.6.102-7
kernel-tools-libs - update to 6.6.102-7
kernel-tools-libs-devel - update to 6.6.102-7
perf - update to 6.6.102-7
python3-perf - update to 6.6.102-7
linux-nvidia-tegra (Ubuntu package) - update to 6.8.0-1035.38