Improper control of a resource through its lifetime in Linux kernel - CVE-2026-43352

 

Improper control of a resource through its lifetime in Linux kernel - CVE-2026-43352

Published: May 9, 2026


Vulnerability identifier: #VU130832
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-43352
CWE-ID: CWE-664
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper state management in the DMA ring abort handling logic in the mipi-i3c-hci driver when processing DMA dequeue operations. A local user can trigger ring abort handling in an invalid ring state to cause a denial of service.

The issue can occur when the ring is already stopped, and the abort sequence may reset hardware ring pointers and disrupt controller state.


Affected software

Linux kernel

How to mitigate CVE-2026-43352

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3

External References

Related Security Bulletins