Boletines de Vulnerabilidades

CVE-2026-43440

   
Software afectado LINUX KERNEL
 
In the Linux kernel, the following vulnerability has been resolved:

net/mana: Null service_wq on setup error to prevent double destroy

In mana_gd_setup() error path, set gc->service_wq to NULL after
destroy_workqueue() to match the cleanup in mana_gd_cleanup().
This prevents a use-after-free if the workqueue pointer is checked
after a failed setup.

Link:

https://nvd.nist.gov/vuln/detail/CVE-2026-43440