CVE-2026-43428

In the Linux kernel, the following vulnerability has been resolved: USB: core: Limit the length of unkillable synchronous timeouts The usb_control_msg(), usb_bulk_msg(), and usb_interrupt_msg() APIs in usbcore allow unlimited timeout durations. And since they use uninterruptible waits, this leaves open the possibility of hanging a task for an indefinitely long time, with no way to kill it short of unplugging the target device. To prevent this sort of problem, enforce a maximum limit on the length of these unkillable timeouts. The limit chosen here, somewhat arbitrarily, is 60 seconds. On many systems (although not all) this is short enough to avoid triggering the kernel's hung-task detector. In addition, clear up the ambiguity of negative timeout values by treating them the same as 0, i.e., using the maximum allowed timeout.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.12:-:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.12:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.12:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.12:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.12:rc5:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc4:*:*:*:*:*:*

History

20 May 2026, 18:26

Type Values Removed Values Added
CPE cpe:2.3:o:linux:linux_kernel:2.6.12:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.12:-:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.12:rc5:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.12:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.12:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc1:*:*:*:*:*:*
First Time Linux linux Kernel
Linux
References () https://git.kernel.org/stable/c/06d2bbc4c66c6b0e8a43728c4949026026a5be67 - () https://git.kernel.org/stable/c/06d2bbc4c66c6b0e8a43728c4949026026a5be67 - Patch
References () https://git.kernel.org/stable/c/1015c27a5e1a63efae2b18a9901494474b4d1dc3 - () https://git.kernel.org/stable/c/1015c27a5e1a63efae2b18a9901494474b4d1dc3 - Patch
References () https://git.kernel.org/stable/c/24b31a227f679a942d820840a4dea7f0c09a387f - () https://git.kernel.org/stable/c/24b31a227f679a942d820840a4dea7f0c09a387f - Patch
References () https://git.kernel.org/stable/c/2d34cb4d1d6283b4be9c78f4a83ed6956d3069ec - () https://git.kernel.org/stable/c/2d34cb4d1d6283b4be9c78f4a83ed6956d3069ec - Patch
References () https://git.kernel.org/stable/c/4e86f5b79e62ded7e3c3ebd688cf5775e618148a - () https://git.kernel.org/stable/c/4e86f5b79e62ded7e3c3ebd688cf5775e618148a - Patch
References () https://git.kernel.org/stable/c/64f3d75633aedc12bdff220e9a4337177430bd9d - () https://git.kernel.org/stable/c/64f3d75633aedc12bdff220e9a4337177430bd9d - Patch
References () https://git.kernel.org/stable/c/659c0c7d50a4b0f6aa197c4c098cfd91daf63862 - () https://git.kernel.org/stable/c/659c0c7d50a4b0f6aa197c4c098cfd91daf63862 - Patch
References () https://git.kernel.org/stable/c/6c62935670acdbb7687ced20494923b66fbb0367 - () https://git.kernel.org/stable/c/6c62935670acdbb7687ced20494923b66fbb0367 - Patch
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
CWE NVD-CWE-noinfo

08 May 2026, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-08 15:16

Updated : 2026-05-20 18:26


NVD link : CVE-2026-43428

Mitre link : CVE-2026-43428

CVE.ORG link : CVE-2026-43428


JSON object : View

Products Affected

linux

  • linux_kernel