PT-2026-38983 · Linux · Linux Kernel
Published
2026-05-08
·
Updated
2026-05-16
·
CVE-2026-43332
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A flaw exists in the thermal core where the
thermal zone device register with trips() function fails to properly handle the error path during thermal zone device registration. If the registration fails after the device is registered, the system does not wait for the tz->removal completion. This can lead to a situation where the tz object is freed prematurely if user space has already taken a reference to the thermal zone device's kobject, as thermal release() might not be called by the error path.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel