Junglewise Threat Intelligence

CVE-2026-43135: Linux Kernel resource leak in cx23885 media driver

CVE-2026-43135 · Severity: medium · CVSS 5.5 · Published 2026-05-06

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's cx23885 driver, which manages certain video and audio capture hardware. A flaw in how the driver handles errors during hardware setup can lead to a resource leak. This could allow a local user to cause a system crash or instability, resulting in a denial of service.

Technical details

A resource leak exists in the cx23885 driver within the Linux kernel's media subsystem. Specifically, the snd_cx23885_hw_params() function in drivers/media/pci/cx23885/cx23885-alsa.c fails to call cx23885_alsa_dma_unmap() when an error occurs during the execution of cx23885_risc_databuffer(). This missing unmap operation in the error path results in a failure to release DMA resources acquired by cx23885_alsa_dma_map(). A local attacker with sufficient privileges to interact with the media device could exploit this to exhaust system resources, leading to a kernel panic or denial of service. Patches have been released across multiple stable kernel branches.

Affected products

  • Linux Linux Kernel 3.18 to 5.10.252, 5.11 to 5.15.202, 5.16 to 6.1.165, 6.2 to 6.6.128, 6.7 to 6.12.75, 6.13 to 6.18.16, 6.19 to 6.19.6

Timeline

  • 2026-05-06: disclosed
  • 2026-05-06: advisory

References

Related threats