Junglewise Threat Intelligence

CVE-2026-43432: Linux Kernel memory leak in xhci_disable_slot

CVE-2026-43432 · Severity: medium · CVSS 5.5 · Published 2026-05-08

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A memory leak vulnerability was identified in the Linux kernel's USB (xHCI) driver. The xHCI driver is responsible for managing USB 3.0 connections. Under specific error conditions when disabling a USB slot, the system fails to properly release allocated memory, which could lead to a gradual depletion of system resources and potential instability or denial of service over time.

Technical details

A memory leak exists in the Linux kernel's USB xHCI driver within the xhci_disable_slot() function. The vulnerability is caused by improper error handling where the code calls kfree() on a command structure instead of xhci_free_command(). While kfree() releases the primary command structure, it fails to release the associated completion structure allocated by xhci_alloc_command(). An attacker or specific hardware failure conditions could trigger these error paths, leading to kernel memory exhaustion. The fix replaces kfree() with xhci_free_command() to ensure all associated structures are properly deallocated. This issue was identified via static analysis and affects mainline kernels up to v6.13-rc1.

Affected products

  • Linux Linux Kernel v6.13-rc1 and earlier versions

Timeline

  • 2026-03-05: other: Patch authored by Zilin Guan
  • 2026-05-08: disclosed: CVE published

References

Related threats