PatchSiren cyber security CVE debrief
CVE-2026-43342 Linux CVE debrief
CVE-2026-43342 affects the Linux kernel’s USB gadget RNDIS function. The issue is a race condition in class, subclass, and protocol option handling when those values are accessed concurrently through configfs. The fix uses an existing mutex to serialize access; the issue was identified during code inspection.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- MEDIUM 4.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-08
- Original CVE updated
- 2026-05-18
- Advisory published
- 2026-05-08
- Advisory updated
- 2026-05-18
Who should care
Linux kernel maintainers, distro security teams, and operators who use USB gadget/RNDIS functionality on affected kernels should prioritize this advisory.
Technical summary
NVD describes the flaw as a CWE-362 race condition in usb: gadget: f_rndis, where class/subclass/protocol options can be accessed concurrently via configfs. That concurrency can create inconsistent state and, per CVSS, has potential availability impact (A:H) with local access required (AV:L) and high attack complexity (AC:H). The NVD record links multiple Linux stable patch references, and the vulnerable version ranges include kernels from 4.14 up to the listed fixed cutoffs, plus Linux 7.0 rc1 through rc6 entries.
Defensive priority
Medium. Prioritize patching if your environment exposes USB gadget/RNDIS functionality or ships kernels in the affected ranges, because the flaw can affect availability even though it requires local access and high attack complexity.
Recommended defensive actions
- Upgrade to a kernel build that includes the stable fix for your branch; NVD lists non-vulnerable cutoffs at 5.10.253, 5.15.203, 6.1.168, 6.6.134, 6.12.81, 6.18.22, and 6.19.12.
- If you cannot upgrade immediately, reduce exposure by disabling or limiting unnecessary USB gadget/RNDIS configfs functionality on systems that do not require it.
- Confirm your vendor kernel has backported the relevant Linux stable patch rather than relying only on upstream branch numbers.
- Check affected systems for use of f_rndis configfs option writes and ensure they are running a patched kernel before enabling related workflows.
- Track distro or vendor advisories tied to the kernel.org stable patch references included with the CVE record.
Evidence notes
The source corpus states that CVE-2026-43342 is in Linux kernel usb: gadget: f_rndis and that the class/subclass/protocol options were susceptible to race conditions through concurrent configfs access. It also states the fix is to protect those options with an existing mutex and that the issue was identified during code inspection. NVD marks the CVE as analyzed, assigns CVSS 3.1 vector AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H with score 4.7, and lists CWE-362. The record includes stable kernel patch links and vulnerable version ranges spanning multiple supported kernel lines.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-43342 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-43342
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-43342 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-43342
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/0a75d97c53477a59c0aa1c65f69038c719f9c5b8
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/209decd3f7901df9842b83f2540dc8685e344a07
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/446f1842cda929c40d4697722bfdcfb334bc9692
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/65b7dbf80a1627667c241fff7c1c224f3118014f
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/7d8fa3b8783ab95a46e20d97fbeeede719b2efda
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/8d8c68b1fc06ece60cf43e1306ff0f4ac121547e
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/c1b3d5b0acb194efe20fc5864ee03439fa7bd45c
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.