PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-43403 Linux CVE debrief

CVE-2026-43403 is a Linux kernel vulnerability in nsfs namespace-iteration ioctls. The documented fix tightens permission checks so that even privileged services do not necessarily see other privileged services’ namespaces, reducing the chance of information leakage across privilege boundaries. NVD rates the issue HIGH (CVSS 8.8) and links kernel patches for remediation.

Vendor
Linux
Product
Unknown
CVSS
HIGH 8.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-08
Original CVE updated
2026-05-21
Advisory published
2026-05-08
Advisory updated
2026-05-21

Who should care

Linux kernel maintainers, distro security teams, and operators of systems running affected kernel releases should care most, especially environments that rely on namespaces, containers, or other multi-tenant service isolation. Because the issue is local and requires privileges, it is most relevant to hosts where multiple privileged workloads share a kernel.

Technical summary

According to the supplied Linux kernel description, the flaw is in nsfs namespace iteration ioctls. The fix centralizes access policy through may_see_all_namespaces(), tightening permission checks so a privileged service cannot automatically enumerate or inspect namespaces owned by another privileged service. NVD lists affected kernel ranges as 6.12 through 6.12.78, 6.13 through 6.18.20, 6.19 through 6.19.9, plus 7.0-rc1 and 7.0-rc2. The NVD CVSS vector is AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H, indicating local exploitation with elevated privileges and potential cross-boundary impact.

Defensive priority

High. This is a kernel-level access-control issue with a high CVSS score and official patch references. Prioritize patching or backporting on systems that run affected kernel branches, especially hosts with containers, namespaces, or multiple privileged services.

Recommended defensive actions

  • Inventory Linux kernel versions and compare them with the affected ranges listed by NVD: 6.12-6.12.78, 6.13-6.18.20, 6.19-6.19.9, 7.0-rc1, and 7.0-rc2.
  • Apply the vendor or stable-kernel patches referenced by NVD as soon as practical, or install a distribution update that backports the fix.
  • Prioritize patching systems that host multiple tenants, containers, or privileged services sharing the same kernel.
  • Validate that your patched kernel includes the nsfs permission-check change using may_see_all_namespaces() or an equivalent vendor backport.
  • Track distro advisories and confirm no local policy exceptions or custom kernel changes reintroduce namespace enumeration exposure.

Evidence notes

The CVE description states that nsfs permission checks for namespace iteration ioctls were tightened to prevent privileged services from seeing other privileged services’ namespaces and leaking information. NVD marks the record analyzed, assigns CVSS 8.8 HIGH with vector AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H, and lists four official kernel patch references. The supplied corpus does not include a CWE beyond NVD-CWE-noinfo, so root-cause categorization is limited to the description and NVD metadata.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-43403 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-43403

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-43403 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-43403

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/0ad650e60150eda789deca5e78a6a09d26bf8fc9

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/2f3dea284c761c890d676f77d5e55c0c496b4ef4

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/3376b345df155ca36d8611857b41ff7d5183fc38

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/e6b899f08066e744f89df16ceb782e06868bd148

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.