Improper Check or Handling of Exceptional Conditions in Linux kernel - CVE-2026-43488
Published: May 14, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper error handling in xhci_irq() when handling a host controller error during UAS storage device plug/unplug scenarios. A local user can trigger repeated device plug/unplug events to cause a denial of service.
The issue can result in an interrupt storm that leads to severe system-level faults.
How to mitigate CVE-2026-43488
Sources
- https://git.kernel.org/stable/c/09ff0099c6cf148ff1f7053b5b6c84beb1c2ef8d
- https://git.kernel.org/stable/c/6f91f3f087194c114d6d8ea4591b850bb00672f8
- https://git.kernel.org/stable/c/b2dd9abf8c06cfcbcf242321fd54ae51a4807705
- https://git.kernel.org/stable/c/cd41e0d1df8fcf5eae294657da52b50d1ce03246
- https://git.kernel.org/stable/c/d6d5febd12452b7fd951fdd15c3ec262f01901a4