PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-43488 Linux CVE debrief

CVE-2026-43488 describes a Linux kernel xHCI error-handling flaw where a Host Controller Error (HCE) may continue generating interrupts instead of stopping cleanly. In the reported UAS storage plug/unplug scenario on Android devices, that can lead to an interrupt storm and severe system-level faults. The fix adds xhci_halt() to the HCE path in xhci_irq(), matching the existing handling used for fatal errors. The patch stops the storm, but does not provide full HCE recovery; proper recovery still requires resetting and re-initializing the xHC.

Vendor
Linux
Product
Unknown
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-13
Original CVE updated
2026-06-26
Advisory published
2026-05-13
Advisory updated
2026-06-26

Who should care

Kernel maintainers, Linux distribution security teams, Android platform integrators, and operators of systems that rely on USB storage/UAS hotplug paths should prioritize this advisory. Systems that can encounter xHCI Host Controller Error conditions are the most relevant, especially where repeated interrupts can destabilize the machine.

Technical summary

The issue is in the Linux kernel USB xHCI interrupt handler. When STS_HCE is observed, the driver previously logged a warning and assumed controller activity would cease per the xHCI specification. On some hosts, interrupts continue after HCE because the interrupt is not cleared, creating an interrupt storm. The mitigation is to halt the controller in the HCE branch via xhci_halt(), similar to the existing STS_FATAL handling. This change addresses the storm condition, but the description notes that complete HCE recovery still requires controller reset and re-initialization.

Defensive priority

High for environments that expose xHCI/UAS hotplug scenarios, because the issue can escalate into a system-wide denial of service or instability. Even without a CVSS score in the supplied corpus, the described impact warrants prompt kernel update assessment.

Recommended defensive actions

  • Review whether your Linux kernels include the upstream/stable xHCI HCE fix referenced by the supplied kernel commits.
  • Prioritize updates on Android devices and other systems that use USB Attached SCSI (UAS) storage with frequent plug/unplug activity.
  • Monitor for repeated xHCI interrupt activity or instability following USB controller error events.
  • If updating is delayed, reduce exposure to USB storage hotplug paths where operationally feasible.
  • Track downstream vendor advisories and kernel backports for the specific xHCI fix rather than relying on the generic CVE text alone.

Evidence notes

All statements above are derived from the supplied CVE description and official references. The CVE was published and modified at 2026-05-13T16:16:52.107Z in the provided corpus. The references point to kernel.org stable commit URLs, which support that the issue was fixed in Linux kernel code, but no version range or CVSS data was provided in the corpus. The vendor field is unresolved/low confidence, so the debrief treats this as a Linux kernel issue rather than naming a specific product vendor.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-43488 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-43488

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-43488 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-43488

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/09ff0099c6cf148ff1f7053b5b6c84beb1c2ef8d

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/6f91f3f087194c114d6d8ea4591b850bb00672f8

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/b2dd9abf8c06cfcbcf242321fd54ae51a4807705

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/cd41e0d1df8fcf5eae294657da52b50d1ce03246

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/d6d5febd12452b7fd951fdd15c3ec262f01901a4

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.