Improper control of a resource through its lifetime in Linux kernel - CVE-2026-43290
Published: May 9, 2026
Linux kernel
Linux Foundation
Description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper state management in the uvcvideo streaming start path when starting video streaming. A local user can repeatedly trigger streaming start failures to cause a denial of service.
The issue occurs when streaming fails to start due to a uvc_pm_get() error.