PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-43431 Linux CVE debrief

CVE-2026-43431 is a Linux kernel xhci bug in recently added portli debugfs files. Under certain hardware layout conditions, reading the debugfs entry can hit a NULL pointer dereference and crash the kernel. NVD rates the issue CVSS 5.5 (medium) with local, low-privilege access and no user interaction required.

Vendor
Linux
Product
Unknown
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-08
Original CVE updated
2026-05-20
Advisory published
2026-05-08
Advisory updated
2026-05-20

Who should care

Linux kernel maintainers, distribution security teams, and operators of systems running affected kernel builds should care, especially where local users may access debugfs-backed xhci diagnostics.

Technical summary

The issue is in xhci debugfs handling for the portli files. The kernel can count more ports in xhci->max_ports than are reported by Supported Protocol capabilities, or encounter gaps between ports of different speeds. In those cases, port->rhub is NULL, so code that assumes it can reach xhci through port->rhub can dereference a null pointer while reading portli debugfs files. The fix adds an explicit NULL check and prints portli in hex without dereferencing port->rhub.

Defensive priority

Medium

Recommended defensive actions

  • Apply the Linux kernel fix referenced by the official kernel.org patch links in the NVD record.
  • Update affected kernels identified by NVD: Linux kernel 6.19 through before 6.19.9, and 7.0-rc1 through 7.0-rc4.
  • Review whether debugfs exposure is necessary on production systems and restrict access where possible.
  • Prioritize validation on systems using xHCI hardware and kernels that include the newly added portli debugfs path.
  • Monitor for unexpected kernel crashes or oopses when diagnostic debugfs files are read.

Evidence notes

Source description states the bug is a NULL pointer dereference in the recently added xhci portli debugfs files. The record says the problem occurs when xhci->max_ports exceeds ports reported by Supported Protocol capabilities or when there are gaps between ports of different speeds, leaving port->rhub NULL. NVD classifies the weakness as CWE-476 and gives CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H. NVD vulnerability status is Analyzed, and the vulnerable CPE criteria cover Linux kernel 6.19 up to but not including 6.19.9, plus 7.0-rc1 through 7.0-rc4.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-43431 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-43431

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-43431 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-43431

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/9c8bef223c6e991276188d30d74bdb2cbd8be652

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/ae4ff9dead5efa2025eddfcdb29411432bf40a7c

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.