cbcvebase.
CVE-2026-43426
published 2026-05-08

CVE-2026-43426: In the Linux kernel, the following vulnerability has been resolved: usb: renesas_usbhs: fix use-after-free in ISR during device removal In usbhs_remove(), the…

PriorityP341high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.13%
2.6th percentile
In the Linux kernel, the following vulnerability has been resolved: usb: renesas_usbhs: fix use-after-free in ISR during device removal In usbhs_remove(), the driver frees resources (including the pipe array) while the interrupt handler (usbhs_interrupt) is still registered. If an interrupt fires after usbhs_pipe_remove() but before the driver is fully unbound, the ISR may access freed memory, causing a use-after-free. Fix this by calling devm_free_irq() before freeing resources. This ensures the interrupt handler is both disabled and synchronized (waits for any running ISR to complete) before usbhs_pipe_remove() is called.

Affected

53 ranges· showing 25
VendorProductVersion rangeFixed in
linuxlinux
linuxlinux>= f1407d5c66240b33d11a7f1a41d55ccf6a9d7647 < c7012fc73dab4829404fedeeaa8531f12ac8545fc7012fc73dab4829404fedeeaa8531f12ac8545f
linuxlinux>= f1407d5c66240b33d11a7f1a41d55ccf6a9d7647 < 51afaf919bbaacdd9cc9e146033ae0a743a42dd751afaf919bbaacdd9cc9e146033ae0a743a42dd7
linuxlinux>= f1407d5c66240b33d11a7f1a41d55ccf6a9d7647 < 1899edac312ef17a7234851686e8a703f56d0a841899edac312ef17a7234851686e8a703f56d0a84
linuxlinux>= f1407d5c66240b33d11a7f1a41d55ccf6a9d7647 < 9c6159d5b72d5fc265cce5da04f27d730b552e699c6159d5b72d5fc265cce5da04f27d730b552e69
linuxlinux>= f1407d5c66240b33d11a7f1a41d55ccf6a9d7647 < 6287e0c01ccb818e7214f88d885ffb7c9e81b0e06287e0c01ccb818e7214f88d885ffb7c9e81b0e0
linuxlinux>= f1407d5c66240b33d11a7f1a41d55ccf6a9d7647 < 0b7d11fd6e742ecc0b1eca44b4f0b93140c74bae0b7d11fd6e742ecc0b1eca44b4f0b93140c74bae
linuxlinux>= f1407d5c66240b33d11a7f1a41d55ccf6a9d7647 < 6ffe44f022c95b1b29c691d2169c5abc046f75806ffe44f022c95b1b29c691d2169c5abc046f7580
linuxlinux>= f1407d5c66240b33d11a7f1a41d55ccf6a9d7647 < 3cbc242b88c607f55da3d0d0d336b49bf1e204123cbc242b88c607f55da3d0d0d336b49bf1e20412
linuxlinux_kernel
linuxlinux_kernel>= 3.0 < 5.10.2535.10.253
linuxlinux_kernel>= 5.11 < 5.15.2035.15.203
linuxlinux_kernel>= 5.16 < 6.1.1676.1.167
linuxlinux_kernel>= 6.13 < 6.18.196.18.19
linuxlinux_kernel>= 6.19 < 6.19.96.19.9
linuxlinux_kernel>= 6.2 < 6.6.1306.6.130
linuxlinux_kernel>= 6.7 < 6.12.786.12.78
ubuntulinux
ubuntulinux-aws
ubuntulinux-aws-5.15
ubuntulinux-aws-fips
ubuntulinux-azure
ubuntulinux-azure-5.15
ubuntulinux-azure-6.8
ubuntulinux-azure-fde

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_ubuntu7.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.