PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-43426 Linux CVE debrief

CVE-2026-43426 is a Linux kernel use-after-free in the Renesas USBHS driver’s interrupt handling during device removal. The public record says usbhs_remove() freed driver resources, including the pipe array, while usbhs_interrupt() was still registered. If an interrupt arrived after usbhs_pipe_remove() but before unbind completed, the ISR could dereference freed memory. The fix moves devm_free_irq() earlier so the interrupt handler is disabled and synchronized before resources are released.

Vendor
Linux
Product
Unknown
CVSS
HIGH 7.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-08
Original CVE updated
2026-05-20
Advisory published
2026-05-08
Advisory updated
2026-05-20

Who should care

Linux kernel maintainers, distribution security teams, and operators of systems that include the renesas_usbhs driver in affected kernel branches. This is most relevant anywhere kernel updates are staged slowly or embedded/industrial deployments remain on older stable releases.

Technical summary

NVD classifies the issue as CWE-416 (use-after-free) with CVSS 3.1 vector AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H. According to the record, affected Linux kernel ranges span multiple stable branches: 3.0 through 5.10.252, 5.11 through 5.15.202, 5.16 through 6.1.166, 6.2 through 6.6.129, 6.7 through 6.12.77, 6.13 through 6.18.18, 6.19 through 6.19.8, plus 7.0-rc1 through 7.0-rc4. The described fix is to call devm_free_irq() before usbhs_pipe_remove(), ensuring the IRQ handler is disabled and any running ISR completes before the driver frees the pipe array and related resources.

Defensive priority

High. The issue is locally reachable, but it affects kernel memory safety and carries high confidentiality, integrity, and availability impact in the CVSS record. Prioritize upgrades on systems that ship or use the affected driver.

Recommended defensive actions

  • Upgrade to a fixed kernel release in the affected branch line: 5.10.253, 5.15.203, 6.1.167, 6.6.130, 6.12.78, 6.18.19, or 6.19.9, as appropriate for your branch.
  • Apply the referenced stable kernel patches from the official kernel.org links if you maintain downstream kernels.
  • Confirm whether your hardware and kernel configuration actually use the renesas_usbhs driver, then prioritize those hosts for remediation.
  • Track device-removal and hot-unplug test paths in validation, because the vulnerable path is in usbhs_remove() and interrupt teardown ordering.
  • If immediate patching is not possible, reduce exposure by limiting local administrative access on affected hosts and accelerating kernel maintenance windows.

Evidence notes

This debrief is based only on the supplied NVD record and official kernel.org patch references. The record lists the issue as analyzed, assigns CWE-416, and provides the CVSS 3.1 vector AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H. The source description explicitly states the removal-time ISR use-after-free and the fix order change involving devm_free_irq() before freeing resources. NVD also supplies vulnerable CPE ranges and patch references on git.kernel.org.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-43426 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-43426

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-43426 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-43426

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/0b7d11fd6e742ecc0b1eca44b4f0b93140c74bae

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/1899edac312ef17a7234851686e8a703f56d0a84

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/3cbc242b88c607f55da3d0d0d336b49bf1e20412

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/51afaf919bbaacdd9cc9e146033ae0a743a42dd7

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/6287e0c01ccb818e7214f88d885ffb7c9e81b0e0

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/6ffe44f022c95b1b29c691d2169c5abc046f7580

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/9c6159d5b72d5fc265cce5da04f27d730b552e69

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.