PatchSiren cyber security CVE debrief
CVE-2026-43440 Linux CVE debrief
CVE-2026-43440 is a Linux kernel use-after-free in the net/mana code path. The issue comes from a setup error path in mana_gd_setup() where the workqueue pointer was not cleared after destroy_workqueue(), creating a mismatch with cleanup logic and a risk of double-destroy or stale-pointer use after a failed setup. NVD rates the issue HIGH with local attack requirements and references kernel patches as the fix.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- HIGH 7.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-08
- Original CVE updated
- 2026-05-21
- Advisory published
- 2026-05-08
- Advisory updated
- 2026-05-21
Who should care
Linux kernel maintainers, distro security teams, and operators of systems running affected kernel versions—especially hosts using the mana driver or related networking paths—should treat this as a priority update item.
Technical summary
NVD maps CVE-2026-43440 to CWE-416 (use after free) and rates it CVSS 3.1 7.8/High (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). The affected ranges listed by NVD are Linux kernel 6.18.16 through 6.18.18, 6.19.6 through 6.19.8, plus 7.0-rc2 and 7.0-rc3. The vendor description says the fix is to set gc->service_wq to NULL after destroy_workqueue() in the mana_gd_setup() error path so later checks do not see a freed pointer.
Defensive priority
High. This is a kernel memory-safety issue with meaningful confidentiality, integrity, and availability impact, and the fix is already reflected in official kernel patch references.
Recommended defensive actions
- Identify Linux systems running kernels in the affected NVD ranges and prioritize them for patching.
- Apply the vendor/stable kernel fixes referenced by the official kernel.org patch links.
- Upgrade to a kernel version outside the affected ranges listed by NVD.
- Verify whether your fleet uses the mana networking driver and focus validation there first.
- After updating, confirm the affected setup and cleanup paths are coming from the patched kernel build.
Evidence notes
Evidence is limited to the official CVE/NVD record and kernel.org patch references supplied in the source corpus. NVD marks the vulnerability as analyzed, assigns CWE-416, and lists three official patch references. The CVE description states the fix is to null gc->service_wq after destroy_workqueue() in mana_gd_setup() to prevent a use-after-free when setup fails.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-43440 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-43440
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-43440 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-43440
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/59489ce60d7412ed82fb1d8002faa3102dcd4916
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/6c92392602b451e3869f15ab685f8f650e942b13
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/87c2302813abc55c46485711a678e3c312b00666
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.