PT-2026-39090 · Linux · Linux Kernel

Published

2026-05-08

·

Updated

2026-05-15

·

CVE-2026-43429

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The usbtmc driver allows users to specify timeout values via an ioctl command, which are then used in usb bulk msg() calls. Because usb bulk msg() employs unkillable waits, a user could provide arbitrarily long timeouts to hang a kernel thread indefinitely. This is addressed by replacing usb bulk msg() with usb bulk msg killable().
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Related Identifiers

CVE-2026-43429
OESA-2026-2312
OESA-2026-2313
OESA-2026-2314

Affected Products

Linux Kernel