Junglewise Threat Intelligence

CVE-2026-43165: Linux Kernel resource leak in nct7363 hwmon driver

CVE-2026-43165 · Severity: medium · CVSS 5.5 · Published 2026-05-06

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A resource leak vulnerability was identified in the Linux kernel's hardware monitoring driver for the NCT7363 chip, which manages fan speeds and PWM signals. This flaw could allow a local user to cause a gradual depletion of system resources, potentially leading to system instability or a denial-of-service condition over time. The issue has been resolved in recent kernel updates.

Technical details

A memory management flaw exists in the nct7363_present_pwm_fanin function within the drivers/hwmon/nct7363.c component of the Linux kernel. The function calls of_parse_phandle_with_args() but fails to subsequently call of_node_put() to release the reference to the device node. This results in a reference count leak (CWE-401). A local attacker with low privileges could potentially exploit this to exhaust kernel memory or resources, leading to a denial-of-service. Patches have been merged into stable kernel branches to ensure the reference is properly released.

Affected products

  • Linux Linux Kernel 6.13 to 6.18.16, 6.19 to 6.19.6

Timeline

  • 2026-01-15: other: Patch authored
  • 2026-05-06: disclosed: CVE published
  • 2026-05-06: advisory

References

Related threats