CVE-2026-43072: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: drm/vc4: platform_get_irq_byname() returns an int platform_get_irq_byname() will return a negative value if an error happens, so it should be checked and not just passed directly into devm_request_threaded_irq() hoping all will be ok.

Affected products

  • Linux Linux Kernel: from 5.15, before 6.6.136 (fixed in 6.6.136); from 6.7, before 6.12.83 (fixed in 6.12.83); from 6.13, before 6.18.24 (fixed in 6.18.24); from 6.19, before 6.19.14 (fixed in 6.19.14); from 7.0, before 7.0.1 (fixed in 7.0.1)

Published 2026-05-05. Last modified 2026-06-17.