CVE-2026-43192
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
06/05/2026
Last modified:
11/05/2026
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
dm mpath: Add missing dm_put_device when failing to get scsi dh name<br />
<br />
When commit fd81bc5cca8f ("scsi: device_handler: Return error pointer in<br />
scsi_dh_attached_handler_name()") added code to fail parsing the path if<br />
scsi_dh_attached_handler_name() failed with -ENOMEM, it didn&#39;t clean up<br />
the reference to the path device that had just been taken. Fix this, and<br />
steamline the error paths of parse_path() a little.
Impact
Base Score 3.x
5.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.19 (including) | 6.19.6 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



