← Back to CVE intelligence
CVE intelligence

CVE-2026-43095

Vulnerability intelligence

Published May 6, 2026Sources checked Oct 9, 2026
5.5MEDIUMCVSS out of 10
What this means

Review the available evidence

CVE-2026-43095 and is rated Medium severity with a CVSS score of 5.5. It is not in the current CISA KEV record we collected. That does not prove exploitation has not occurred.

What to do next

Remediation and response

Ubuntu Security Notices guidance

Vendor revision: Oct 9, 2026

This update corrects flaws in the following subsystems: - Hardware crypto device drivers; - NVIDIA Tegra memory controller driver; - Network drivers; - USB core drivers; - GFS2 file system; - OCFS2 file system; - SMB network file system; - SoundWire (SDCA) ASoC drivers; - B.A.T.M.A.N.

CISA KEVNot listedBased on the latest collected catalog
EPSS0.1%Estimated 30-day exploitation probability
Ransomware useNot markedCISA KEV ransomware field
Threat actors0Source-linked actor relationships
Overview

What is CVE-2026-43095?

In the Linux kernel, the following vulnerability has been resolved:

ASoC: SDCA: Fix errors in IRQ cleanup

IRQs are enabled through sdca_irq_populate() from component probe using devm_request_threaded_irq(), this however means the IRQs can persist if the sound card is torn down. Some of the IRQ handlers store references to the card and the kcontrols which can then fail.

Some detail of the crash was explained in [1].

Generally it is not advised to use devm outside of bus probe, so the code is updated to not use devm. The IRQ requests are not moved to bus probe time as it makes passing the snd_soc_component into the IRQs very awkward and would the require a second step once the component is available, so it is simpler to just register the IRQs at this point, even though that necessitates some manual cleanup.

Source: NVD