PatchSiren cyber security CVE debrief
CVE-2026-43432 Linux CVE debrief
CVE-2026-43432 is a Linux kernel xHCI bug that leaks memory in an error-handling path inside xhci_disable_slot(). According to the supplied record, xhci_alloc_command() can allocate both a command structure and a completion structure, but the buggy path freed only the command with kfree(), leaving the completion object behind. The fix is to use xhci_free_command(), which releases both allocations correctly.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-08
- Original CVE updated
- 2026-05-20
- Advisory published
- 2026-05-08
- Advisory updated
- 2026-05-20
Who should care
Linux fleet owners, kernel maintainers, and platform teams running systems with USB/xHCI support should care most. The issue is local and requires the right device/state conditions, but it can still cause availability degradation over time on affected kernels.
Technical summary
The supplied NVD record classifies the issue as CWE-401 and gives it CVSS 3.1 vector AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H (5.5 MEDIUM). The vulnerability is a memory leak in usb:xhci error handling: xhci_disable_slot() used kfree() on a command object that may also own a completion structure allocated by xhci_alloc_command(). Because xhci_free_command() frees both pieces, replacing kfree() with that helper resolves the leak. NVD lists affected Linux kernel version ranges across multiple release lines, and the record includes kernel patch references for the fix.
Defensive priority
Medium — patch as part of routine kernel maintenance, and prioritize systems that run affected Linux kernel lines with active USB/xHCI use or broad local user access.
Recommended defensive actions
- Apply the kernel fix or a vendor backport that replaces kfree() with xhci_free_command() in xhci_disable_slot().
- Check deployed kernels against the affected version ranges listed by NVD and prioritize any hosts in the 4.19, 5.4, 5.10, 5.15, 5.16, 6.2, 6.7, 6.13, 6.19, or 7.0-rc lines.
- Plan a reboot into the patched kernel after update, since the issue is in kernel memory management.
- Use the official kernel patch references in the record to confirm your distro or vendor has incorporated the fix.
- Treat this as an availability hardening item rather than a confidentiality or integrity exposure, based on the supplied CVSS vector.
Evidence notes
The description and NVD metadata indicate a Linux kernel USB xHCI memory leak resolved by using xhci_free_command() instead of kfree() in xhci_disable_slot(). NVD marks the vulnerability as analyzed, assigns CWE-401, and provides CVSS 3.1 AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H. The supplied dates show the CVE was published on 2026-05-08 and modified on 2026-05-20. The record also states the bug was found by an experimental static analysis tool on v6.13-rc1, verified to persist in mainline, and not reliably triggered in runtime testing because the error paths require specific hardware/state conditions.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-43432 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-43432
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-43432 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-43432
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/078b446efc0f5e496c31bccb72b98af979963a83
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/1e800e26d54ccf2ddf2ea6d6cbe021c804d8aa62
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/2e2baa8fb5aa4d080cbfeb84c51eff797529f413
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/46aea90763832cd6e9b0c2e1c00e6a9512156d4b
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/6288baf0c8c4dcfbf206773aede9c1f2269cec28
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/807e4fb5140c73eb5dba1e399a990db5c1f3cdf8
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/c1c8550e70401159184130a1afc6261db01fc0ce
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.