Race condition in Linux kernel - CVE-2026-43324
Published: May 9, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a race condition in the dummy-hcd driver callback handling when disabling emulated interrupts during gadget driver unbind. A local user can trigger gadget unbind operations to cause a denial of service.
The issue can result in a callback handler still running while the gadget driver is being unbound.
How to mitigate CVE-2026-43324
Sources
- https://git.kernel.org/stable/c/2ca9e46f8f1f5a297eb0ac83f79d35d5b3a02541
- https://git.kernel.org/stable/c/5687a09776069bd915560021c9728ca528440128
- https://git.kernel.org/stable/c/5aa776c8615bea3b1eaeec87b0788375800ead4f
- https://git.kernel.org/stable/c/8bcd80219d8e10e660bf29b20e41bb8beb4e4cb7
- https://git.kernel.org/stable/c/94d4fab1dd9e64f45449bcc7d6a5acf796b13015
- https://git.kernel.org/stable/c/cbf7df5e5d27cd5bea92ee9a75a4b28dbcc718d4
- https://git.kernel.org/stable/c/d847f375b1bcea713143bc02720d13d2d01b012a