Junglewise Threat Intelligence

CVE-2026-43257: Linux Kernel cx88 resource leak in snd_cx88_hw_params

CVE-2026-43257 · Severity: medium · CVSS 5.5 · Published 2026-05-06

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's cx88 driver, which supports certain video capture and tuner hardware. A flaw in how the system handles errors during audio setup can lead to a resource leak, where memory or hardware mappings are not properly released. This could allow a local user to cause a system crash or instability (denial of service) by repeatedly triggering these error conditions.

Technical details

A resource management vulnerability (CWE-772) exists in the cx88-alsa component of the Linux kernel. Specifically, in the `snd_cx88_hw_params()` function within `drivers/media/pci/cx88/cx88-alsa.c`, the code fails to call `cx88_alsa_dma_unmap()` when `cx88_risc_databuffer()` returns an error. This results in a failure to release DMA resources acquired by a previous call to `cx88_alsa_dma_map()`. A local attacker with sufficient privileges to interact with the media hardware could exploit this to exhaust system resources or cause a kernel panic. The issue has been resolved by adding the missing unmap call to the error path in multiple stable kernel branches.

Affected products

  • Linux Linux Kernel 3.19 to 5.10.252, 5.11 to 5.15.202, 5.16 to 6.1.165, 6.2 to 6.6.128, 6.7 to 6.12.75, 6.13 to 6.18.16, 6.19 to 6.19.6

Timeline

  • 2026-05-06: disclosed: CVE published by kernel.org
  • 2026-05-11: advisory: NIST NVD advisory published
  • 2026-01-13: patched: Initial patch committed to mainline kernel

References

Related threats