PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-43425 Linux CVE debrief

CVE-2026-43425 is a Linux kernel USB driver issue in the mdc800 path. If mdc800_device_read() times out while waiting for download_urb completion, it can return without killing the URB, so a later read() may resubmit an URB that is still active and trigger the warning “URB submitted while active.” NVD rates this as medium severity with local, low-privilege access and high availability impact.

Vendor
Linux
Product
Unknown
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-08
Original CVE updated
2026-05-20
Advisory published
2026-05-08
Advisory updated
2026-05-20

Who should care

Linux kernel maintainers, distro security teams, and operators of systems that use the mdc800 USB image driver should review this issue. It is most relevant where the affected kernel versions are deployed and the driver may be present or loadable.

Technical summary

The bug is a timeout-handling flaw in usb: image: mdc800. The read path submits download_urb and waits for completion; on timeout, it previously returned without cancelling the URB. That leaves the request in flight, and a subsequent read() can try to submit the same URB again, which triggers the usb_submit_urb() warning. The fix is to check the return value of wait_event_timeout() and kill the URB when a timeout occurs before inspecting status or resubmitting. NVD lists affected Linux kernel version ranges spanning older 2.6.12 releases and multiple stable series up through the listed end-excluded versions.

Defensive priority

Medium. This is not marked as a known exploited vulnerability in the supplied data, but it can affect kernel availability and generate repeated warnings or denial-of-service conditions on systems using the driver.

Recommended defensive actions

  • Apply the upstream/stable kernel patches linked by NVD for CVE-2026-43425.
  • Upgrade to a Linux kernel release that includes the fix for the affected branch you run.
  • If you cannot patch immediately, minimize use of the mdc800 driver on affected systems and monitor for repeated USB kernel warnings.
  • Inventory kernels against the NVD affected version ranges before and after remediation.

Evidence notes

The CVE description states that mdc800_device_read() can return on wait_event_timeout() expiration without killing download_urb, leaving the URB active and enabling a later read() to resubmit it. NVD marks the issue as analyzed with CVSS 3.1 AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H and provides multiple kernel patch references. The supplied NVD CPE criteria list affected Linux kernel ranges ending before 5.10.253, 5.15.203, 6.1.167, 6.6.130, 6.12.78, 6.18.19, and 6.19.9, plus the specific early 2.6.12 and 7.0 release-candidate entries.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-43425 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-43425

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-43425 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-43425

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/15536f6c15f48037a1672cbdea53266d67861ff6

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/155f471e38aa516f6c58c2ae03ca3dc222fa2fdb

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/1be3b77de4eb89af8ae2fd6610546be778e25589

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/9bf877cc67309b2a063b0087c3ad8585fb11cec3

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/9fa5a49760979ba016506fe292a431c8b83f043e

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/b7fed917f84e484e06c5e9926746d0b524e3a93e

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/cc7398447810c9450c90d092efe9997569f8d96f

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.