Improper control of a resource through its lifetime in Linux kernel - CVE-2026-43345
Published: May 9, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper register field definition in the IPA GSI event ring configuration logic when initializing event rings on IPA v5.0+ hardware. A local user can trigger channel operations that wait for transfer completion to cause a denial of service.
The issue can cause runtime suspend, system suspend, and remoteproc stop operations to hang indefinitely, and the IPA data path may become non-functional.
How to mitigate CVE-2026-43345
Sources
- https://git.kernel.org/stable/c/2bf18b643c4656413f7cfd5615af60a6b4e261da
- https://git.kernel.org/stable/c/2d2dc166d55148cfcf8ae67b415f8d6d110e6fca
- https://git.kernel.org/stable/c/34c988bb04cbdf093d2134e179433da49ffcd044
- https://git.kernel.org/stable/c/56007972c0b1e783ca714d6f1f4d6e66e531d21f
- https://git.kernel.org/stable/c/ae8343a19ccb051d519dbb3a9082ddea9f0551d3