CVE-2026-43372: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: net: dsa: microchip: Fix error path in PTP IRQ setup If request_threaded_irq() fails during the PTP message IRQ setup, the newly created IRQ mapping is never disposed. Indeed, the ksz_ptp_irq_setup()'s error path only frees the mappings that were successfully set up. Dispose the newly created mapping if the associated request_threaded_irq() fails at setup.

Affected products

  • Linux Linux Kernel: from 6.6.119, before 6.6.130 (fixed in 6.6.130); from 6.12.61, before 6.12.78 (fixed in 6.12.78); from 6.17.11, before 6.18 (fixed in 6.18); from 6.18.1, before 6.18.19 (fixed in 6.18.19); from 6.19, before 6.19.9 (fixed in 6.19.9); version 6.18 only; …

Published 2026-05-08. Last modified 2026-06-17.