Improper resource shutdown or release in Linux kernel - CVE-2026-43343
Published: May 9, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper resource shutdown or release in geth_free in the usb gadget f_subset function when unlinking the function and reconfiguring attributes via configfs. A local user can unlink the function and attempt to configure attributes via configfs to cause a denial of service.
How to mitigate CVE-2026-43343
Sources
- https://git.kernel.org/stable/c/23e4851ce348a329d974e84e828155dda9f52122
- https://git.kernel.org/stable/c/3d436670b47415da042452618fb5d8e317ab095f
- https://git.kernel.org/stable/c/3f5bfc550a40d7493b1cf09540ed6b412b3b82be
- https://git.kernel.org/stable/c/75776a055b656873319c3830fed471daef3ceb23
- https://git.kernel.org/stable/c/a932b171554714b1bca313b853c7aa9f2930f9aa
- https://git.kernel.org/stable/c/caa27923aacd8a5869207842f2ab1657c6c0c7bc
- https://git.kernel.org/stable/c/cc8ec610cd14c093a19371691a7ce1ee5421e829
- https://git.kernel.org/stable/c/d7d702407b61e96286a15b6e715572f541a8d41c