PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-43440 Linux CVE debrief

CVE-2026-43440 is a Linux kernel use-after-free in the net/mana code path. The issue comes from a setup error path in mana_gd_setup() where the workqueue pointer was not cleared after destroy_workqueue(), creating a mismatch with cleanup logic and a risk of double-destroy or stale-pointer use after a failed setup. NVD rates the issue HIGH with local attack requirements and references kernel patches as the fix.

Vendor
Linux
Product
Unknown
CVSS
HIGH 7.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-08
Original CVE updated
2026-05-21
Advisory published
2026-05-08
Advisory updated
2026-05-21

Who should care

Linux kernel maintainers, distro security teams, and operators of systems running affected kernel versions—especially hosts using the mana driver or related networking paths—should treat this as a priority update item.

Technical summary

NVD maps CVE-2026-43440 to CWE-416 (use after free) and rates it CVSS 3.1 7.8/High (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). The affected ranges listed by NVD are Linux kernel 6.18.16 through 6.18.18, 6.19.6 through 6.19.8, plus 7.0-rc2 and 7.0-rc3. The vendor description says the fix is to set gc->service_wq to NULL after destroy_workqueue() in the mana_gd_setup() error path so later checks do not see a freed pointer.

Defensive priority

High. This is a kernel memory-safety issue with meaningful confidentiality, integrity, and availability impact, and the fix is already reflected in official kernel patch references.

Recommended defensive actions

  • Identify Linux systems running kernels in the affected NVD ranges and prioritize them for patching.
  • Apply the vendor/stable kernel fixes referenced by the official kernel.org patch links.
  • Upgrade to a kernel version outside the affected ranges listed by NVD.
  • Verify whether your fleet uses the mana networking driver and focus validation there first.
  • After updating, confirm the affected setup and cleanup paths are coming from the patched kernel build.

Evidence notes

Evidence is limited to the official CVE/NVD record and kernel.org patch references supplied in the source corpus. NVD marks the vulnerability as analyzed, assigns CWE-416, and lists three official patch references. The CVE description states the fix is to null gc->service_wq after destroy_workqueue() in mana_gd_setup() to prevent a use-after-free when setup fails.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-43440 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-43440

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-43440 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-43440

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/59489ce60d7412ed82fb1d8002faa3102dcd4916

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/6c92392602b451e3869f15ab685f8f650e942b13

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/87c2302813abc55c46485711a678e3c312b00666

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.