Executive brief
A vulnerability was identified in the Linux kernel's COMEDI subsystem, which handles data acquisition from various hardware devices. When certain devices are reconfigured to use different drivers, the system fails to properly reset internal security locks, leading to inconsistent states. This could potentially allow a local user to cause a system crash or interfere with hardware operations.
Technical details
A vulnerability exists in the COMEDI subsystem of the Linux kernel where `struct comedi_device->spinlock` is not reinitialized between attachments to different low-level drivers. When devices are attached via the `COMEDI_DEVCONFIG` ioctl, a mismatch in locking levels between successive drivers can result in inconsistent lock states. This is particularly problematic when `CONFIG_LOCKDEP` is enabled, as it triggers incorrect lock-dependency tracking. The fix involves explicitly calling `spin_lock_init` on the device spinlock within `comedi_device_attach` before the new driver's attach function is executed.
Affected products
- Linux Linux Kernel All versions prior to the 2026 fix
Timeline
- 2026-02-25: patched: Initial patch authored by Ian Abbott
- 2026-05-08: disclosed: CVE-2026-43340 published
References
- https://git.kernel.org/stable/c/2b1f49e4fdff3ef0f8e9158bbb5b149e06287560
- https://git.kernel.org/stable/c/3181c34b415c5464be9d34bff3e43ef63b747039
- https://git.kernel.org/stable/c/430291d8f3884f57ae0057049b0ca291453e29e1
- https://git.kernel.org/stable/c/4b9a9a6d71e3e252032f959fb3895a33acb5865c
- https://git.kernel.org/stable/c/4d5ffe524903a30e2e0da7d16841a56bec2de55c
- https://git.kernel.org/stable/c/83134a7a176ce5b4b19b6edecf4360e8d98d1a5a
- https://git.kernel.org/stable/c/b89c026227712c367950bbae055a5b31073d3b30