PatchSiren cyber security CVE debrief
CVE-2026-43419 Linux CVE debrief
CVE-2026-43419 is a Linux kernel Ceph client bug that can leak memory in ceph_mdsc_build_path() when error paths fail to release a path buffer allocated with __getname(). The upstream fix adds the missing __putname() cleanup before returning when ownership is not transferred to the caller. This is primarily a stability and resource-consumption issue rather than a direct code-execution flaw.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-08
- Original CVE updated
- 2026-05-12
- Advisory published
- 2026-05-08
- Advisory updated
- 2026-05-12
Who should care
Linux kernel maintainers, distro security teams, and operators running systems that use the Ceph client in kernel space should review this fix. Environments with heavy metadata/path handling activity are the most likely to notice resource impact from repeated leaks.
Technical summary
The vulnerability description states that ceph_mdsc_build_path() allocates a path buffer with __getname(), but some error code paths returned without freeing it. The fix ensures __putname() is called whenever the pointer is not handed off via path_info.path. Based on the supplied record, the issue is a memory leak in error handling for the Ceph filesystem path-building logic in the Linux kernel.
Defensive priority
Low to medium. The issue is an availability/resource-management problem with a published fix, but the supplied record does not indicate code execution, privilege escalation, or active exploitation.
Recommended defensive actions
- Apply the Linux kernel patch that adds the missing __putname() cleanup in ceph_mdsc_build_path().
- Prioritize rollout on systems that enable and actively use the Ceph client.
- Monitor affected hosts for unusual memory growth or instability if patching is delayed.
- Track kernel and distro advisories for backported fixes that correspond to the referenced upstream commits.
- If you maintain downstream kernels, verify the fix is present in all supported branches that include the Ceph client code.
Evidence notes
The supplied CVE description explicitly says the fix resolves memory leaks in ceph_mdsc_build_path() by adding __putname() calls on error paths that did not free the path pointer obtained by __getname(). The NVD record provided in the corpus lists the vulnerability status as 'Undergoing Analysis' and includes five kernel.org stable commit references. No CVSS score, KEV entry, or weaponized exploitation information was provided in the source corpus.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-43419 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-43419
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-43419 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-43419
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/040d159a45ded7f33201421a81df0aa2a86e5a0b
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/097cd68f46686391a98f2618188f0cb7b7570de2
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/13b8b9d6f59ef17fb96c298c3a0d62a8306950cc
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/5895d0164c84d7fec6abc198920c257f55c51899
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/657dc653b06a3cc0282aea447a3f137fa94066a4
416baaa9-dc9f-4396-8d5f-8c081fb06d67
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.