CVE-2026-43138
published 2026-05-06CVE-2026-43138: In the Linux kernel, the following vulnerability has been resolved: reset: gpio: suppress bind attributes in sysfs This is a special device that's created…
PriorityP340high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.13%
3.3th percentile
In the Linux kernel, the following vulnerability has been resolved:
reset: gpio: suppress bind attributes in sysfs
This is a special device that's created dynamically and is supposed to
stay in memory forever. We also currently don't have a devlink between
it and the actual reset consumer. Suppress sysfs bind attributes so that
user-space can't unbind the device because - as of now - it will cause a
use-after-free splat from any user that puts the reset control handle.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| linux | linux | — | — |
| linux | linux | >= cee544a40e4426040946e685988b1489f13e6600 < 09d6efc6abd42809956d598906c222ccd1c8ae92 | 09d6efc6abd42809956d598906c222ccd1c8ae92 |
| linux | linux | >= cee544a40e4426040946e685988b1489f13e6600 < 76801c3dfca0ac6339a23e9615b5f23e25b8644c | 76801c3dfca0ac6339a23e9615b5f23e25b8644c |
| linux | linux | >= cee544a40e4426040946e685988b1489f13e6600 < 1d7d869f074f98c34fe23f6a56e5f3acc1f95a2b | 1d7d869f074f98c34fe23f6a56e5f3acc1f95a2b |
| linux | linux | >= cee544a40e4426040946e685988b1489f13e6600 < 16de4c6a8fe9ff497ca1aba33ef0dbee09f11952 | 16de4c6a8fe9ff497ca1aba33ef0dbee09f11952 |
| linux | linux_kernel | >= 6.13 < 6.18.16 | 6.18.16 |
| linux | linux_kernel | >= 6.19 < 6.19.6 | 6.19.6 |
| linux | linux_kernel | >= 6.9 < 6.12.75 | 6.12.75 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Linux Kernel up to 6.12.74/6.18.15/6.19.5 use after free (WID-SEC-2026-1405)
vuldb·2026-05-18·CVSS 7.8
CVE-2026-43138 [HIGH] Linux Kernel up to 6.12.74/6.18.15/6.19.5 use after free (WID-SEC-2026-1405)
A vulnerability classified as critical was found in Linux Kernel up to 6.12.74/6.18.15/6.19.5. Affected by this vulnerability is an unknown functionality. Executing a manipulation can lead to use after free.
This vulnerability appears as CVE-2026-43138. The attacker needs to be present on the local network. There is no available exploit.
Upgrading the affected component is advised.
GHSA
GHSA-3xm2-xcvm-ghrh: In the Linux kernel, the following vulnerability has been resolved:
reset: gpio: suppress bind attributes in sysfs
This is a special device that's c
ghsa_unreviewed·2026-05-06
CVE-2026-43138 GHSA-3xm2-xcvm-ghrh: In the Linux kernel, the following vulnerability has been resolved:
reset: gpio: suppress bind attributes in sysfs
This is a special device that's c
In the Linux kernel, the following vulnerability has been resolved:
reset: gpio: suppress bind attributes in sysfs
This is a special device that's created dynamically and is supposed to
stay in memory forever. We also currently don't have a devlink between
it and the actual reset consumer. Suppress sysfs bind attributes so that
user-space can't unbind the device because - as of now - it will cause a
use-after-free splat from any user that puts the reset control handle.
Red Hat
kernel: reset: gpio: suppress bind attributes in sysfs
vendor_redhat·2026-05-06
CVE-2026-43138 CWE-825 kernel: reset: gpio: suppress bind attributes in sysfs
kernel: reset: gpio: suppress bind attributes in sysfs
A flaw was found in the Linux kernel. A local user could exploit a vulnerability in the GPIO (General Purpose Input/Output) reset controller by unbinding a dynamically created device through the sysfs (a virtual filesystem providing an interface to kernel data structures) interface. This improper handling of device unbinding can lead to a use-after-free condition, which may result in system instability or a denial of service.
Package: kernel (Red Hat Enterprise Linux 10) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Not affected
Package: kernel (Red Hat Enterprise Linux 8) - Not affected
Pack
No detection rules found.
No public exploits indexed.
2026-05-06
Published