The SentinelOne Annual Threat Report - A Defenders Guide from the FrontlinesThe SentinelOne Annual Threat ReportGet the Report
Experiencing a Breach?Blog
Get StartedContact Us
SentinelOne
  • Platform
    Platform Overview
    • Singularity Platform
      Welcome to Integrated Enterprise Security
    • AI for Security
      Leading the Way in AI-Powered Security Solutions
    • Securing AI
      Accelerate AI Adoption with Secure AI Tools, Apps, and Agents.
    • How It Works
      The Singularity XDR Difference
    • Singularity Marketplace
      One-Click Integrations to Unlock the Power of XDR
    • Pricing & Packaging
      Comparisons and Guidance at a Glance
    Data & AI
    • Purple AI
      Accelerate SecOps with Generative AI
    • Singularity Hyperautomation
      Easily Automate Security Processes
    • AI-SIEM
      The AI SIEM for the Autonomous SOC
    • AI Data Pipelines
      Security Data Pipeline for AI SIEM and Data Optimization
    • Singularity Data Lake
      AI-Powered, Unified Data Lake
    • Singularity Data Lake for Log Analytics
      Seamlessly Ingest Data from On-Prem, Cloud or Hybrid Environments
    Endpoint Security
    • Singularity Endpoint
      Autonomous Prevention, Detection, and Response
    • Singularity XDR
      Native & Open Protection, Detection, and Response
    • Singularity RemoteOps Forensics
      Orchestrate Forensics at Scale
    • Singularity Threat Intelligence
      Comprehensive Adversary Intelligence
    • Singularity Vulnerability Management
      Application & OS Vulnerability Management
    • Singularity Identity
      Identity Threat Detection and Response
    Cloud Security
    • Singularity Cloud Security
      Block Attacks with an AI-Powered CNAPP
    • Singularity Cloud Native Security
      Secure Cloud and Development Resources
    • Singularity Cloud Workload Security
      Real-Time Cloud Workload Protection Platform
    • Singularity Cloud Data Security
      AI-Powered Threat Detection for Cloud Storage
    • Singularity Cloud Security Posture Management
      Detect and Remediate Cloud Misconfigurations
    Securing AI
    • Prompt Security
      Secure AI Tools Across Your Enterprise
  • Why SentinelOne?
    Why SentinelOne?
    • Why SentinelOne?
      Cybersecurity Built for What’s Next
    • Our Customers
      Trusted by the World’s Leading Enterprises
    • Industry Recognition
      Tested and Proven by the Experts
    • About Us
      The Industry Leader in Autonomous Cybersecurity
    Compare SentinelOne
    • Arctic Wolf
    • Broadcom
    • CrowdStrike
    • Cybereason
    • Microsoft
    • Palo Alto Networks
    • Sophos
    • Splunk
    • Trellix
    • Trend Micro
    • Wiz
    Verticals
    • Energy
    • Federal Government
    • Finance
    • Healthcare
    • Higher Education
    • K-12 Education
    • Manufacturing
    • Retail
    • State and Local Government
  • Services
    Managed Services
    • Managed Services Overview
      Wayfinder Threat Detection & Response
    • Threat Hunting
      World-Class Expertise and Threat Intelligence
    • Managed Detection & Response
      24/7/365 Expert MDR Across Your Entire Environment
    • Incident Readiness & Response
      DFIR, Breach Readiness, & Compromise Assessments
    Support, Deployment, & Health
    • Technical Account Management
      Customer Success with Personalized Service
    • SentinelOne GO
      Guided Onboarding & Deployment Advisory
    • SentinelOne University
      Live and On-Demand Training
    • Services Overview
      Comprehensive Solutions for Seamless Security Operations
    • SentinelOne Community
      Community Login
  • Partners
    Our Network
    • MSSP Partners
      Succeed Faster with SentinelOne
    • Singularity Marketplace
      Extend the Power of S1 Technology
    • Cyber Risk Partners
      Enlist Pro Response and Advisory Teams
    • Technology Alliances
      Integrated, Enterprise-Scale Solutions
    • SentinelOne for AWS
      Hosted in AWS Regions Around the World
    • Channel Partners
      Deliver the Right Solutions, Together
    • SentinelOne for Google Cloud
      Unified, Autonomous Security Giving Defenders the Advantage at Global Scale
    • Partner Locator
      Your Go-to Source for Our Top Partners in Your Region
    Partner Portal→
  • Resources
    Resource Center
    • Case Studies
    • Data Sheets
    • eBooks
    • Reports
    • Videos
    • Webinars
    • Whitepapers
    • Events
    View All Resources→
    Blog
    • Feature Spotlight
    • For CISO/CIO
    • From the Front Lines
    • Identity
    • Cloud
    • macOS
    • SentinelOne Blog
    Blog→
    Tech Resources
    • SentinelLABS
    • Ransomware Anthology
    • Cybersecurity 101
  • About
    About SentinelOne
    • About SentinelOne
      The Industry Leader in Cybersecurity
    • Investor Relations
      Financial Information & Events
    • SentinelLABS
      Threat Research for the Modern Threat Hunter
    • Careers
      The Latest Job Opportunities
    • Press & News
      Company Announcements
    • Cybersecurity Blog
      The Latest Cybersecurity Threats, News, & More
    • FAQ
      Get Answers to Our Most Frequently Asked Questions
    • DataSet
      The Live Data Platform
    • S Foundation
      Securing a Safer Future for All
    • S Ventures
      Investing in the Next Generation of Security, Data and AI
  • Pricing
Get StartedContact Us
CVE Vulnerability Database
Vulnerability Database/CVE-2026-43142

CVE-2026-43142: Linux Kernel Media Iris DoS Vulnerability

CVE-2026-43142 is a denial of service vulnerability in the Linux kernel media iris driver that causes memory waste through stale buffer allocations. This article covers technical details, affected versions, and mitigation.

Published: May 7, 2026

CVE-2026-43142 Overview

CVE-2026-43142 is a memory leak vulnerability in the Linux kernel's iris gen1 media driver. The driver failed to destroy internal buffers after the firmware released them, leaving stale allocations that persisted until session close. The issue is most pronounced across resolution changes, where new buffers are allocated to meet updated requirements while old buffers remain orphaned in memory. The Linux kernel maintainers have resolved the issue by destroying internal buffers once the release response is received from the firmware.

Critical Impact

Stale buffer allocations in the iris gen1 media driver waste kernel memory across video session lifetimes, particularly during resolution transitions.

Affected Products

  • Linux kernel iris gen1 media driver
  • Stable kernel branches referenced in upstream commits 1dabf00ee206, 7cde76db8883, and d4457f23ac01
  • Distributions packaging affected kernel versions prior to backport

Discovery Timeline

  • 2026-05-06 - CVE-2026-43142 published to NVD
  • 2026-05-06 - Last updated in NVD database

Technical Details for CVE-2026-43142

Vulnerability Analysis

The vulnerability resides in the iris gen1 video codec driver under the Linux kernel media subsystem. The driver coordinates internal buffer allocations with firmware running on the hardware codec. When the firmware signals that it has released its internal buffers, the driver is expected to free the corresponding kernel-side allocations. The pre-patch driver did not perform this teardown, leaving allocations resident in memory after they were no longer referenced by either the firmware or the active session state.

During video sessions, resolution changes trigger reallocation of internal buffers sized to the new dimensions. Each transition compounds the leak because newly allocated buffers coexist with stale ones from prior resolutions. Memory is reclaimed only when the session closes, which can be a long-running operation in streaming or transcoding workloads.

The EPSS score for this issue is 0.017%, reflecting low likelihood of weaponized exploitation. The classification falls under Memory Leak in the broader category of resource management defects.

Root Cause

The root cause is missing buffer destruction logic in the firmware release response handler. The driver acknowledged the firmware release event but did not invoke the cleanup path that frees the associated kernel buffer descriptors and backing memory.

Attack Vector

The vulnerability is a local resource exhaustion issue rather than a remote code execution vector. A local user with access to the iris media device can trigger sustained memory consumption by initiating video sessions with frequent resolution changes. There is no published exploit, no CISA KEV listing, and no evidence of in-the-wild exploitation.

The vulnerability manifests in the firmware buffer release callback path. See the upstream kernel commits referenced in the Kernel Git Commit Details for the exact code paths modified.

Detection Methods for CVE-2026-43142

Indicators of Compromise

  • Sustained growth of kernel slab allocations attributable to the iris driver across long-running media sessions
  • Increased kmalloc consumption correlating with resolution change events in video pipelines
  • Out-of-memory conditions on systems running iris gen1 media workloads without recent kernel updates

Detection Strategies

  • Audit running kernel versions against the patched commits 1dabf00ee206, 7cde76db8883, and d4457f23ac01 to identify unpatched hosts
  • Monitor /proc/slabinfo and /proc/meminfo for unexplained growth on systems exercising the iris media driver
  • Use ftrace or perf to trace allocations in the iris buffer release path during resolution change events

Monitoring Recommendations

  • Track kernel memory baselines on devices using Qualcomm iris-class video codecs and alert on deviations
  • Correlate user-space media session activity with kernel memory pressure metrics
  • Include kernel version inventory in vulnerability management reporting to surface unpatched hosts

How to Mitigate CVE-2026-43142

Immediate Actions Required

  • Apply the upstream Linux kernel patches referenced by commits 1dabf00ee206eceb0f08a1fe5d1ce635f9064338, 7cde76db8883ec8a3d1456068079ecadbfb15ca5, and d4457f23ac0130240053a34be663f0fade3bb371
  • Update to a distribution kernel package that incorporates the fix once released by the vendor
  • Inventory devices using the iris gen1 media driver and prioritize kernel updates on systems running long-lived video workloads

Patch Information

The fix destroys internal buffers in the firmware release response handler, ensuring kernel-side allocations are freed when the firmware signals release. Refer to the Kernel Git Commit Details for the patch implementation.

Workarounds

  • Restart media sessions periodically to force buffer reclamation on unpatched kernels
  • Limit workloads that perform frequent resolution changes on affected systems until the patch is deployed
  • Restrict access to the iris media device to trusted local users to reduce the attack surface for resource exhaustion

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

  • Vulnerability Details
  • TypeDOS

  • Vendor/TechLinux Kernel

  • SeverityNONE

  • CVSS ScoreN/A

  • EPSS Probability0.02%

  • Known ExploitedNo
  • Impact Assessment
  • ConfidentialityNone
  • IntegrityNone
  • AvailabilityNone
  • Technical References
  • Kernel Git Commit Details

  • Kernel Git Commit Details

  • Kernel Git Commit Details
  • Related CVEs
  • CVE-2026-43492: Linux Kernel MPI Integer Underflow DoS

  • CVE-2026-43491: Linux Kernel QRTR NS DoS Vulnerability

  • CVE-2026-43329: Linux Kernel Netfilter DoS Vulnerability

  • CVE-2026-43331: Linux Kernel DOS Vulnerability
Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.

Try SentinelOne
  • Get Started
  • Get a Demo
  • Product Tour
  • Why SentinelOne
  • Pricing & Packaging
  • FAQ
  • Contact
  • Contact Us
  • Customer Support
  • SentinelOne Status
  • Language
  • Platform
  • Singularity Platform
  • Singularity Endpoint
  • Singularity Cloud
  • Singularity AI-SIEM
  • Singularity Identity
  • Singularity Marketplace
  • Purple AI
  • Services
  • Wayfinder TDR
  • SentinelOne GO
  • Technical Account Management
  • Support Services
  • Verticals
  • Energy
  • Federal Government
  • Finance
  • Healthcare
  • Higher Education
  • K-12 Education
  • Manufacturing
  • Retail
  • State and Local Government
  • Cybersecurity for SMB
  • Resources
  • Blog
  • Labs
  • Case Studies
  • Videos
  • Product Tours
  • Events
  • Cybersecurity 101
  • eBooks
  • Webinars
  • Whitepapers
  • Press
  • News
  • Ransomware Anthology
  • Company
  • About Us
  • Our Customers
  • Careers
  • Partners
  • Legal & Compliance
  • Security & Compliance
  • Investor Relations
  • S Foundation
  • S Ventures

©2026 SentinelOne, All Rights Reserved.

Privacy Notice Terms of Use

English