CVE-2026-43332: Linux Kernel

High severity, CVSS 7.8. EPSS: 0.1% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: thermal: core: Fix thermal zone device registration error path If thermal_zone_device_register_with_trips() fails after registering a thermal zone device, it needs to wait for the tz->removal completion like thermal_zone_device_unregister(), in case user space has managed to take a reference to the thermal zone device's kobject, in which case thermal_release() may not be called by the error path itself and tz may be freed prematurely. Add the missing wait_for_completion() call to the thermal zone device registration error path.

Affected products

  • Linux Linux Kernel: from 6.6.14, before 6.6.134 (fixed in 6.6.134); from 6.8, before 6.12.81 (fixed in 6.12.81); from 6.13, before 6.18.22 (fixed in 6.18.22); from 6.19, before 6.19.12 (fixed in 6.19.12); version 6.7.2 only; version 7.0 only

Published 2026-05-08. Last modified 2026-06-17.