PT-2026-39056 · Linux · Linux Kernel

Published

2026-05-08

·

Updated

2026-05-21

·

CVE-2026-43395

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A memory leak occurs in the Linux kernel when the xe sync entry parse() function fails during parsing. The function may allocate references for syncobj, fence, chain fence, or user fence before encountering a failure path. Because some of these paths return directly without proper cleanup, partially initialized states are left behind, leading to leaked references.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

CVE-2026-43395

Affected Products

Linux Kernel