CVE-2026-43138: reset: gpio: suppress bind attributes in sysfs

Published May 6, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

reset: gpio: suppress bind attributes in sysfs

This is a special device that's created dynamically and is supposed to stay in memory forever. We also currently don't have a devlink between it and the actual reset consumer. Suppress sysfs bind attributes so that user-space can't unbind the device because - as of now - it will cause a use-after-free splat from any user that puts the reset control handle.

Affected Software

4 affected components
Linux Linux kernel
Linux Linux kernel>=6.9<6.12.75
Linux Linux kernel>=6.13<6.18.16
Linux Linux kernel>=6.19<6.19.6

Event History

May 6, 2026
CVE Published
via MITRE·11:27 AM
Data Sourced
via MITRE·11:27 AM
Description
Data Sourced
via NVD·12:16 PM
RemedyDescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What access does an attacker need to exploit this issue?

The CVSS vector indicates local access with low privileges is required. No user interaction is required.

2

What action triggers the use-after-free condition?

The condition occurs when user space unbinds the dynamically created GPIO reset device through its sysfs bind attributes. A later user of the reset-control handle can then trigger a use-after-free.

3

What can be done if the patch cannot be deployed immediately?

Prevent user space from unbinding the affected dynamically created device through its sysfs bind attributes. The fix removes those attributes to stop this unbind path.

4

What is the potential security impact?

The CVSS vector rates confidentiality, integrity, and availability impacts as high. The reported flaw is a use-after-free in the Linux kernel.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203