Junglewise Threat Intelligence

CVE-2026-43196: Linux Kernel double free in TI PRUSS pruss_clk_mux_setup

CVE-2026-43196 · Severity: high · CVSS 7.8 · Published 2026-05-06

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's Texas Instruments PRUSS driver, which manages Programmable Real-Time Unit subsystems used in industrial communication. A technical error in how the system handles memory during hardware setup could allow a local attacker to cause a system crash or potentially execute unauthorized code. This impact could lead to a complete loss of system availability or unauthorized access to sensitive data on affected industrial or embedded devices.

Technical details

A double free vulnerability exists in the Linux kernel within the `drivers/soc/ti/pruss.c` component. The root cause is located in the `pruss_clk_mux_setup()` function, where `devm_add_action_or_reset()` is used to register a cleanup handler. On an error path, `devm_add_action_or_reset()` triggers the cleanup function `pruss_of_free_clk_provider()`, which calls `of_node_put()`. However, the calling function also executes `of_node_put()` upon receiving the error return, leading to a double free of the same node pointer. A local attacker with low privileges could exploit this to cause a kernel panic (DoS) or potentially achieve arbitrary code execution. Patches have been released across multiple stable kernel branches to ensure the function returns immediately after the reset action.

Affected products

  • Linux Linux kernel 5.10 to 5.10.252, 5.11 to 5.15.202, 5.16 to 6.1.165, 6.2 to 6.6.128, 6.7 to 6.12.75, 6.13 to 6.18.16, 6.19 to 6.19.6

Timeline

  • 2026-01-13: other: Patch submitted by developer
  • 2026-05-06: disclosed
  • 2026-05-06: advisory

References

Related threats