cbcvebase.
CVE-2026-43007
published 2026-05-01

CVE-2026-43007: In the Linux kernel, the following vulnerability has been resolved: accel/qaic: Handle DBC deactivation if the owner went away When a DBC is released, the…

PriorityP341high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.13%
2.9th percentile
In the Linux kernel, the following vulnerability has been resolved: accel/qaic: Handle DBC deactivation if the owner went away When a DBC is released, the device sends a QAIC_TRANS_DEACTIVATE_FROM_DEV transaction to the host over the QAIC_CONTROL MHI channel. QAIC handles this by calling decode_deactivate() to release the resources allocated for that DBC. Since that handling is done in the qaic_manage_ioctl() context, if the user goes away before receiving and handling the deactivation, the host will be out-of-sync with the DBCs available for use, and the DBC resources will not be freed unless the device is removed. If another user loads and requests to activate a network, then the device assigns the same DBC to that network, QAIC will "indefinitely" wait for dbc->in_use = false, leading the user process to hang. As a solution to this, handle QAIC_TRANS_DEACTIVATE_FROM_DEV transactions that are received after the user has gone away.

Affected

35 ranges· showing 25
VendorProductVersion rangeFixed in
linuxlinux
linuxlinux>= 129776ac2e38231fa9c02ce20e116c99de291666 < 2dd67966f39a2abf8ccb4865031c722e40e01b7f2dd67966f39a2abf8ccb4865031c722e40e01b7f
linuxlinux>= 129776ac2e38231fa9c02ce20e116c99de291666 < 08021f2d4a557d6491e3bcc288e96425f50aa3cf08021f2d4a557d6491e3bcc288e96425f50aa3cf
linuxlinux>= 129776ac2e38231fa9c02ce20e116c99de291666 < f403094d9075d7c565a3d81002b781c325cb3c07f403094d9075d7c565a3d81002b781c325cb3c07
linuxlinux>= 129776ac2e38231fa9c02ce20e116c99de291666 < ee0180e77e6c8482644569632065411de844c515ee0180e77e6c8482644569632065411de844c515
linuxlinux>= 129776ac2e38231fa9c02ce20e116c99de291666 < 2feec5ae5df785658924ab6bd91280dc3926507c2feec5ae5df785658924ab6bd91280dc3926507c
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 6.13 < 6.18.226.18.22
linuxlinux_kernel>= 6.19 < 6.19.126.19.12
linuxlinux_kernel>= 6.4 < 6.6.1346.6.134
linuxlinux_kernel>= 6.7 < 6.12.816.12.81
ubuntulinux
ubuntulinux-aws
ubuntulinux-azure
ubuntulinux-azure-6.8
ubuntulinux-azure-fde
ubuntulinux-azure-fde-6.8
ubuntulinux-azure-fips
ubuntulinux-fips
ubuntulinux-gcp
ubuntulinux-gcp-6.8
ubuntulinux-gcp-fips
ubuntulinux-gke
ubuntulinux-gkeop

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_redhat5.5MEDIUM
vendor_ubuntu2.0LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.