CVE 7.8 HIGH

thermal: core: Fix thermal zone device registration error path_CVE-2026-43332

7.8 / 10
HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Description

In the Linux kernel, the following vulnerability has been resolved:

thermal: core: Fix thermal zone device registration error path

If thermal_zone_device_register_with_trips() fails after registering
a thermal zone device, it needs to wait for the tz->removal completion
like thermal_zone_device_unregister(), in case user space has managed
to take a reference to the thermal zone device's kobject, in which case
thermal_release() may not be called by the error path itself and tz may
be freed prematurely.

Add the missing wait_for_completion() call to the thermal zone device
registration error path.

Basic Information

ID CVE-2026-43332
Source Linux
Published May 8, 2026 at 13:31
Modified May 11, 2026 at 06:33

Affected Product

Vendor Linux
Product Linux
Version 335176dd8ebaca6493807dceea33c478305667fa
Affected Versions Linux Linux 335176dd8ebaca6493807dceea33c478305667fa
Linux Linux 04e6ccfc93c5a1aa1d75a537cf27e418895e20ea
Linux Linux 04e6ccfc93c5a1aa1d75a537cf27e418895e20ea
Linux Linux 04e6ccfc93c5a1aa1d75a537cf27e418895e20ea
Linux Linux 04e6ccfc93c5a1aa1d75a537cf27e418895e20ea
Linux Linux 02871710b93058eb1249d5847c0b2d1c2c3c98ae
Linux Linux 6.8

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.