Junglewise Threat Intelligence

CVE-2026-43177: Linux Kernel Intel IPU6 reference leak in ipu6_pci_probe

CVE-2026-43177 · Severity: medium · CVSS 5.5 · Published 2026-05-06

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's Intel IPU6 camera driver could allow a local user to cause a resource leak. This occurs when the system fails to properly release power management references during certain error conditions. Over time, this could lead to system instability or prevent the hardware from entering low-power states, potentially impacting system availability.

Technical details

A resource management vulnerability exists in the ipu6_pci_probe() function within the Intel IPU6 driver (drivers/media/pci/intel/ipu6/ipu6.c). Several error handling paths used 'goto' statements that bypassed the necessary pm_runtime_put_sync() call, leading to a reference leak. A local attacker could potentially exploit this to cause a denial of service by exhausting system resources or preventing proper power state transitions. The issue has been resolved by adding a new exit label that ensures the runtime PM reference is released before cleaning up other resources. Fixes are available in stable kernel branches 6.12.75, 6.18.16, and 6.19.6.

Affected products

  • Linux Linux Kernel 6.10 to 6.12.75, 6.13 to 6.18.16, 6.19 to 6.19.6

Timeline

  • 2025-12-23: other: Patch authored
  • 2026-05-06: disclosed: CVE published
  • 2026-05-12: advisory: NVD enrichment added

References

Related threats