CVE-2026-43181
MEDIUM EPSS 2.6%
Published May 6, 20262mo ago · Modified Jun 17, 20262w ago
5.5 CVSS 3.1
Published May 6, 2026 2mo ago
Last Modified Jun 17, 2026 2w ago
Description
In the Linux kernel, the following vulnerability has been resolved: gpio: sysfs: fix chip removal with GPIOs exported over sysfs Currently if we export a GPIO over sysfs and unbind the parent GPIO controller, the exported attribute will remain under /sys/class/gpio because once we remove the parent device, we can no longer associate the descriptor with it in gpiod_unexport() and never drop the final reference. Rework the teardown code: provide an unlocked variant of gpiod_unexport() and remove all exported GPIOs with the sysfs_lock taken before unregistering the parent device itself. This is done to prevent any new exports happening before we unregister the device completely.
CVSS Details
Base Score
Exploitability
Impact
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Attack Vector Local
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality None
Integrity None
Availability High
Threat Intelligence
EPSS Exploit Probability
2.6% percentile
Exploit & Patch Status
No Known Exploit
Patch Available
Affected Products 2
References 3
- git.kernel.org https://git.kernel.org/stable/c/54f463494eb5bf193ef7d904a493474c451734df
- git.kernel.org https://git.kernel.org/stable/c/6766f59012301f1bf3f46c6e7149caca45d92309
- git.kernel.org https://git.kernel.org/stable/c/a645cc25904b0baf508b77a0402ce151212b9800
Remediation
- git.kernel.org https://git.kernel.org/stable/c/54f463494eb5bf193ef7d904a493474c451734df
- git.kernel.org https://git.kernel.org/stable/c/6766f59012301f1bf3f46c6e7149caca45d92309
- git.kernel.org https://git.kernel.org/stable/c/a645cc25904b0baf508b77a0402ce151212b9800