PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-43420 Linux CVE debrief

CVE-2026-43420 describes a race in the Linux kernel Ceph client during asynchronous unlink handling. The issue can cause the inode link count (`i_nlink`) to be decremented after it has already been updated to zero by a concurrent completion or capability update, which can trigger a kernel WARNING in `drop_nlink()`. The source description ties the problem to the async unlink path in `ceph_unlink()`, where unlink submission is issued before completion is received. If another client, or the completion of the same unlink, updates the inode state first, the later decrement can underrun the counter. The described impact is kernel warning/log noise and inconsistent inode accounting behavior in the Ceph client path.

Vendor
Linux
Product
Unknown
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-08
Original CVE updated
2026-05-12
Advisory published
2026-05-08
Advisory updated
2026-05-12

Who should care

Linux distribution maintainers, kernel operators, and teams running Ceph-mounted filesystems on Linux should pay attention, especially if async unlink activity is common or kernel warnings are monitored as service-impact signals.

Technical summary

The vulnerable path is in the Linux kernel Ceph client. During async unlink, `ceph_unlink()` submits `CEPH_MDS_OP_UNLINK` and does not wait for completion before calling `drop_nlink()`. In the window between submission and the local decrement, worker-thread processing of capability grants, imports, or the unlink reply can run `set_nlink()` and update the inode link count. If that updated value is already zero, the subsequent decrement in `drop_nlink()` underruns the counter and can emit a WARNING at `fs/inode.c:407`. The source description says the fix is to avoid decrementing when the count is already zero, with locking around `i_nlink` updates using `ceph_inode_info.i_ceph_lock` to prevent TOCTOU races.

Defensive priority

Medium

Recommended defensive actions

  • Apply the upstream/stable Linux kernel fix for CVE-2026-43420 in any kernel that includes the Ceph client async unlink path.
  • Prioritize patching hosts that mount Ceph filesystems and generate frequent unlink activity, since the issue is in the Ceph client path.
  • Review kernel logs for `drop_nlink()` warnings and Ceph unlink-related stack traces as indicators of exposure.
  • Validate vendor kernel backports against the referenced stable kernel fixes before rollout.
  • If you maintain custom Ceph client or kernel changes, avoid ad hoc workarounds and align with the locking-based fix described in the source record.

Evidence notes

The supplied CVE description states that the Linux kernel Ceph client can underrun `i_nlink` during async unlink when concurrent worker activity updates the inode before `drop_nlink()` runs, producing a WARNING in `drop_nlink+0x50/0x68`. The CVE record was published on 2026-05-08 and modified on 2026-05-12; NVD listed the item as undergoing analysis in the supplied source snapshot. The record includes multiple upstream/stable kernel references, supporting that a kernel-side fix exists or was tracked in stable branches.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-43420 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-43420

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-43420 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-43420

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/6d5fd8bb574bef039eb3b738e523870433a2aeb9

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/7db008e85a5d17b64bc5390b828bf457ae91a415

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/8975b85b0d45ca811ace6fac5907652f2310e5ac

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/9b31e88ac5623d15c8bc46f69dfe1d3b43a8f67c

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/aedd29386b23f3e1e6818943e11abfff2953732f

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/b3f5513141ecc6b277a8f7b7efe58a0cf9a5e859

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/ce0123cbb4a40a2f1bbb815f292b26e96088639f

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.