PatchSiren cyber security CVE debrief
CVE-2026-43420 Linux CVE debrief
CVE-2026-43420 describes a race in the Linux kernel Ceph client during asynchronous unlink handling. The issue can cause the inode link count (`i_nlink`) to be decremented after it has already been updated to zero by a concurrent completion or capability update, which can trigger a kernel WARNING in `drop_nlink()`. The source description ties the problem to the async unlink path in `ceph_unlink()`, where unlink submission is issued before completion is received. If another client, or the completion of the same unlink, updates the inode state first, the later decrement can underrun the counter. The described impact is kernel warning/log noise and inconsistent inode accounting behavior in the Ceph client path.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-08
- Original CVE updated
- 2026-05-12
- Advisory published
- 2026-05-08
- Advisory updated
- 2026-05-12
Who should care
Linux distribution maintainers, kernel operators, and teams running Ceph-mounted filesystems on Linux should pay attention, especially if async unlink activity is common or kernel warnings are monitored as service-impact signals.
Technical summary
The vulnerable path is in the Linux kernel Ceph client. During async unlink, `ceph_unlink()` submits `CEPH_MDS_OP_UNLINK` and does not wait for completion before calling `drop_nlink()`. In the window between submission and the local decrement, worker-thread processing of capability grants, imports, or the unlink reply can run `set_nlink()` and update the inode link count. If that updated value is already zero, the subsequent decrement in `drop_nlink()` underruns the counter and can emit a WARNING at `fs/inode.c:407`. The source description says the fix is to avoid decrementing when the count is already zero, with locking around `i_nlink` updates using `ceph_inode_info.i_ceph_lock` to prevent TOCTOU races.
Defensive priority
Medium
Recommended defensive actions
- Apply the upstream/stable Linux kernel fix for CVE-2026-43420 in any kernel that includes the Ceph client async unlink path.
- Prioritize patching hosts that mount Ceph filesystems and generate frequent unlink activity, since the issue is in the Ceph client path.
- Review kernel logs for `drop_nlink()` warnings and Ceph unlink-related stack traces as indicators of exposure.
- Validate vendor kernel backports against the referenced stable kernel fixes before rollout.
- If you maintain custom Ceph client or kernel changes, avoid ad hoc workarounds and align with the locking-based fix described in the source record.
Evidence notes
The supplied CVE description states that the Linux kernel Ceph client can underrun `i_nlink` during async unlink when concurrent worker activity updates the inode before `drop_nlink()` runs, producing a WARNING in `drop_nlink+0x50/0x68`. The CVE record was published on 2026-05-08 and modified on 2026-05-12; NVD listed the item as undergoing analysis in the supplied source snapshot. The record includes multiple upstream/stable kernel references, supporting that a kernel-side fix exists or was tracked in stable branches.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-43420 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-43420
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-43420 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-43420
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/6d5fd8bb574bef039eb3b738e523870433a2aeb9
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/7db008e85a5d17b64bc5390b828bf457ae91a415
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/8975b85b0d45ca811ace6fac5907652f2310e5ac
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/9b31e88ac5623d15c8bc46f69dfe1d3b43a8f67c
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/aedd29386b23f3e1e6818943e11abfff2953732f
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/b3f5513141ecc6b277a8f7b7efe58a0cf9a5e859
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/ce0123cbb4a40a2f1bbb815f292b26e96088639f
416baaa9-dc9f-4396-8d5f-8c081fb06d67
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.