Junglewise Threat Intelligence

CVE-2026-43064: Linux Kernel idxd driver resource leak in DSA/IAA device release

CVE-2026-43064 · Severity: medium · CVSS 5.5 · Published 2026-05-05

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability exists in the Linux kernel's data acceleration driver (idxd) where system resources are not properly cleaned up when a device is removed. This can lead to a resource leak that may eventually cause system instability or a denial-of-service condition. The issue affects systems using Intel Data Streaming Accelerator (DSA) or In-Memory Analytics Accelerator (IAA) hardware.

Technical details

A resource leak vulnerability exists in the dmaengine idxd driver within the Linux kernel. The root cause is a failure to call destroy_workqueue() in the idxd_conf_device_release() function when a device object is freed. An attacker with local access could potentially trigger this leak repeatedly to exhaust system resources, leading to a denial-of-service (DoS). The vulnerability affects the handling of Intel DSA and IAA devices. Patches have been released across multiple stable kernel branches to ensure the workqueue is properly destroyed during the device release lifecycle.

Affected products

  • Linux Linux Kernel 5.11.22 to 5.12, 5.12.5 to 5.13, 5.13 to 6.1.168, 6.2 to 6.6.131, 6.7 to 6.12.80, 6.13 to 6.18.21, 6.19 to 6.19.11, 7.0-rc1 to 7.0-rc5

Timeline

  • 2026-05-05: disclosed
  • 2026-05-05: advisory
  • 2026-02-25: patched: Initial patch committed to mainline kernel tree.

References

Related threats