PT-2026-37590 · Linux+2 · Linux Kernel+2

CVE-2026-43250

·

Published

2026-01-08

·

Updated

2026-08-25

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The ChipIdea UDC driver fails to properly unmap DMA buffers or clean up scatter-gather bounce buffers when the ep nuke() function is called during a USB device disconnection during an active transfer. This occurs because the num mapped sgs field and sgt.sgl pointer retain stale values. If the gadget driver reuses the request upon reconnection without reinitialization, the hardware enqueue() function may skip DMA mapping and use invalid DMA addresses, potentially leading to memory corruption and alignment errors.
Recommendations Update the Linux kernel to a version where the ep nuke() function includes calls to usb gadget unmap request by dev() when num mapped sgs is set and sglist do debounce() when a bounce buffer exists.

Exploit

Fix

RCE

Memory Corruption

Buffer Overflow

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-85881
BDU:2026-12726
CVE-2026-43250
OPENSUSE-SU-2026:21555-1
SUSE-SU-2026:23066-1
SUSE-SU-2026:23068-1
SUSE-SU-2026:23221-1
SUSE-SU-2026:23231-1
SUSE-SU-2026:23237-1
USN-8492-1
USN-8492-2
USN-8492-3
USN-8492-4
USN-8492-5
USN-8497-1
USN-8498-1
USN-8499-1
USN-8606-1
USN-8607-1
USN-8609-1
USN-8619-1

Affected Products

Linuxmint
Linux Kernel
Ubuntu