CVE-2026-43340 Details
Description
In the Linux kernel, the following vulnerability has been resolved: comedi: Reinit dev->spinlock between attachments to low-level drivers `struct comedi_device` is the main controlling structure for a COMEDI device created by the COMEDI subsystem. It contains a member `spinlock` containing a spin-lock that is initialized by the COMEDI subsystem, but is reserved for use by a low-level driver attached to the COMEDI device (at least since commit 25436dc9d84f ("Staging: comedi: remove RT code")). Some COMEDI devices (those created on initialization of the COMEDI subsystem when the "comedi.comedi_num_legacy_minors" parameter is non-zero) can be attached to different low-level drivers over their lifetime using the `COMEDI_DEVCONFIG` ioctl command. This can result in inconsistent lock states being reported when there is a mismatch in the spin-lock locking levels used by each low-level driver to which the COMEDI device has been attached. Fix it by reinitializing `dev->spinlock` before calling the low-level driver's `attach` function pointer if `CONFIG_LOCKDEP` is enabled.
A vulnerability exists in the Linux kernel's COMEDI subsystem, specifically within the 'comedi_device' structure, which is crucial for managing COMEDI devices. This structure includes a spinlock that, while initialized by the COMEDI subsystem, is intended for use by low-level drivers attached to the COMEDI device. The issue arises because certain COMEDI devices can be reattached to different low-level drivers over time, leading to potential mismatches in the spinlock's state. When this happens, inconsistent locking behaviors can occur, depending on the locking practices of the various drivers. The vulnerability can be exploited by attaching a COMEDI device to different low-level drivers, creating a mismatch in the spinlock's state and causing inconsistent lock behaviors.
The vulnerability has been addressed by modifying the COMEDI driver's attachment process. The COMEDI subsystem now reinitializes the spinlock before attaching a low-level driver, ensuring that any previous lock dependencies are cleared. Users should update to the latest stable version of the Linux kernel where this fix has been applied.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/2b1f49e4fdff3ef0f8e9158bbb5b149e06287560 | kernel.org | Patch |
| https://git.kernel.org/stable/c/3181c34b415c5464be9d34bff3e43ef63b747039 | kernel.org | Patch |
| https://git.kernel.org/stable/c/430291d8f3884f57ae0057049b0ca291453e29e1 | kernel.org | Patch |
| https://git.kernel.org/stable/c/4b9a9a6d71e3e252032f959fb3895a33acb5865c | kernel.org | Patch |
| https://git.kernel.org/stable/c/4d5ffe524903a30e2e0da7d16841a56bec2de55c | kernel.org | Patch |
| https://git.kernel.org/stable/c/83134a7a176ce5b4b19b6edecf4360e8d98d1a5a | kernel.org | Patch |
| https://git.kernel.org/stable/c/b89c026227712c367950bbae055a5b31073d3b30 | kernel.org | Patch |
| https://git.kernel.org/stable/c/c01bcc67a9a692d65508ebd480405b5e77d562b7 | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 2.6.29, < 5.10.253 >= 5.11, < 5.15.203 >= 5.16, < 6.1.168 >= 6.2, < 6.6.134 >= 6.7, < 6.12.81 >= 6.13, < 6.18.22 >= 6.19, < 6.19.12 7.0 rc1 7.0 rc2 7.0 rc3 7.0 rc4 7.0 rc5 7.0 rc6 7.0 rc7 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | kernel.org |
| May 15, 2026 | Initial Analysis | [email protected] |
| May 8, 2026 | New CVE Received | kernel.org |