CVE-2026-43440: Linux Kernel

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: net/mana: Null service_wq on setup error to prevent double destroy In mana_gd_setup() error path, set gc->service_wq to NULL after destroy_workqueue() to match the cleanup in mana_gd_cleanup(). This prevents a use-after-free if the workqueue pointer is checked after a failed setup.

Affected products

  • Linux Linux Kernel: from 6.18.16, before 6.18.19 (fixed in 6.18.19); from 6.19.6, before 6.19.9 (fixed in 6.19.9); version 7.0 only

Published 2026-05-08. Last modified 2026-06-17.