PatchSiren cyber security CVE debrief
CVE-2026-43073 Linux CVE debrief
CVE-2026-43073 concerns a Linux kernel x86-64 helper that was misleadingly named and had an awkward interface. The source description says the routine is neither a true user-copy helper nor a non-cached source copy; it is a specialty copy path that uses non-temporal stores for the destination and exception handling for both source and destination accesses. The patch set renames the helper, adjusts its prototype, and updates NTB code to use the corrected interface. Based on the supplied corpus, this looks like a kernel API misuse and cleanup issue rather than a confirmed exploitation case.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-05
- Original CVE updated
- 2026-06-07
- Advisory published
- 2026-05-05
- Advisory updated
- 2026-06-07
Who should care
Linux kernel maintainers, distro security teams, and operators running x86-64 kernels that include drivers or subsystems using this helper, especially NTB or persistent-memory related code. Kernel developers who call the helper directly should also review their usage.
Technical summary
The affected helper, __copy_user_nocache(), was described in the kernel commit message as a misnamed memory-copy routine. It uses non-temporal stores on the destination side, supports exception handling on both source and destination accesses, and is not inherently a user-copy routine. The fix renames the function to a more accurate name, changes the prototype so callers pass a normal size_t and do not rely on an implicit user-pointer interface, and updates NTB code that had been using the user-copy version with STAC/CLAC despite not needing user-space access semantics.
Defensive priority
Medium for code review and patch adoption; low confidence for exploitation risk because the supplied record does not include a CVSS score, exploit details, or confirmed impact. Prioritize if you maintain affected x86-64 kernel paths or vendor trees that carried the old helper interface.
Recommended defensive actions
- Review kernel trees and downstream patches for calls to the old __copy_user_nocache() interface.
- Apply the upstream Linux kernel changes referenced by the supplied stable.git commit links.
- Audit NTB and persistent-memory related code for any direct use of the helper or similar non-temporal copy paths.
- Verify that callers use the corrected interface and that any required user-space access setup remains explicit and local to the caller.
- Track vendor advisories and NVD updates, since the supplied NVD record is still marked Undergoing Analysis.
Evidence notes
All substantive claims are drawn from the supplied CVE description and the referenced upstream Linux kernel stable.git commits. The corpus indicates the issue is a rename/prototype correction and misuse cleanup in x86-64 kernel code; it does not provide CVSS data, exploitability details, affected version ranges, or a confirmed attack scenario. CVE publishedAt: 2026-05-05T16:16:16.650Z; modifiedAt: 2026-05-06T13:08:07.970Z. NVD vulnStatus in the supplied source is Undergoing Analysis.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-43073 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-43073
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-43073 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-43073
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/14b9194db4a28421a4dbe5d6e519efbaa7c5f3cd
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/c6d4e0599e7e73abc04e2488dfeb7940c4039660
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/d187a86de793f84766ea40b9ade7ac60aabbb4fe
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/d993e1723aa2a085aa0d72e70ea889031fc225b4
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/efea91ad1729ff1853d7418e4d3bc27d085e72d0
416baaa9-dc9f-4396-8d5f-8c081fb06d67
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.