PT-2026-38983 · Linux · Linux Kernel

Published

2026-05-08

·

Updated

2026-05-16

·

CVE-2026-43332

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A flaw exists in the thermal core where the thermal zone device register with trips() function fails to properly handle the error path during thermal zone device registration. If the registration fails after the device is registered, the system does not wait for the tz->removal completion. This can lead to a situation where the tz object is freed prematurely if user space has already taken a reference to the thermal zone device's kobject, as thermal release() might not be called by the error path.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Related Identifiers

CVE-2026-43332

Affected Products

Linux Kernel