PT-2026-36424 · Linux+1 · Linux Kernel+1

CVE-2026-43007

·

Published

2026-05-01

·

Updated

2026-08-20

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the accel/qaic component where the host may become out-of-sync with available Doorbell Control (DBC) resources if a user disconnects before a QAIC TRANS DEACTIVATE FROM DEV transaction is processed. This occurs because the decode deactivate() function, which releases DBC resources, is executed within the qaic manage ioctl() context. If the user is no longer present, resources are not freed unless the device is removed. Consequently, if a subsequent user requests to activate a network and is assigned the same DBC, the system will wait indefinitely for the dbc->in use variable to become false, causing the user process to hang.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Double Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-43007
OPENSUSE-SU-2026:21555-1
SUSE-SU-2026:23066-1
SUSE-SU-2026:23068-1
SUSE-SU-2026:23193-1
SUSE-SU-2026:23194-1
SUSE-SU-2026:23221-1
SUSE-SU-2026:23231-1
SUSE-SU-2026:23237-1
SUSE-SU-2026:23241-1
SUSE-SU-2026:23244-1
SUSE-SU-2026:3130-1
SUSE-SU-2026:3166-1
USN-8567-1
USN-8574-1
USN-8574-2
USN-8574-3
USN-8595-1
USN-8595-2
USN-8595-3
USN-8596-1
USN-8606-1
USN-8607-1
USN-8608-1
USN-8609-1
USN-8619-1
USN-8665-1

Affected Products

Linux Kernel
Ubuntu