cbcvebase.
CVE-2026-43138
published 2026-05-06

CVE-2026-43138: In the Linux kernel, the following vulnerability has been resolved: reset: gpio: suppress bind attributes in sysfs This is a special device that's created…

PriorityP340high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.13%
3.3th percentile
In the Linux kernel, the following vulnerability has been resolved: reset: gpio: suppress bind attributes in sysfs This is a special device that's created dynamically and is supposed to stay in memory forever. We also currently don't have a devlink between it and the actual reset consumer. Suppress sysfs bind attributes so that user-space can't unbind the device because - as of now - it will cause a use-after-free splat from any user that puts the reset control handle.

Affected

8 ranges
VendorProductVersion rangeFixed in
linuxlinux
linuxlinux>= cee544a40e4426040946e685988b1489f13e6600 < 09d6efc6abd42809956d598906c222ccd1c8ae9209d6efc6abd42809956d598906c222ccd1c8ae92
linuxlinux>= cee544a40e4426040946e685988b1489f13e6600 < 76801c3dfca0ac6339a23e9615b5f23e25b8644c76801c3dfca0ac6339a23e9615b5f23e25b8644c
linuxlinux>= cee544a40e4426040946e685988b1489f13e6600 < 1d7d869f074f98c34fe23f6a56e5f3acc1f95a2b1d7d869f074f98c34fe23f6a56e5f3acc1f95a2b
linuxlinux>= cee544a40e4426040946e685988b1489f13e6600 < 16de4c6a8fe9ff497ca1aba33ef0dbee09f1195216de4c6a8fe9ff497ca1aba33ef0dbee09f11952
linuxlinux_kernel>= 6.13 < 6.18.166.18.16
linuxlinux_kernel>= 6.19 < 6.19.66.19.6
linuxlinux_kernel>= 6.9 < 6.12.756.12.75
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.