CVE-2026-43138

medium Red Hat
Published: May 6, 2026 (8 days ago)
Last Modified: May 6, 2026
Vendor: Red Hat
Source: REDHAT

Description

A flaw was found in the Linux kernel. A local user could exploit a vulnerability in the GPIO (General Purpose Input/Output) reset controller by unbinding a dynamically created device through the sysfs (a virtual filesystem providing an interface to kernel data structures) interface. This improper handling of device unbinding can lead to a use-after-free condition, which may result in system instability or a denial of service.

CWE

CWE-825

Affected Products

Red Hat Enterprise Linux 10Red Hat Enterprise Linux 6Red Hat Enterprise Linux 7Red Hat Enterprise Linux 8Red Hat Enterprise Linux 9

References