PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-43448 Linux CVE debrief

CVE-2026-43448 is a Linux kernel race condition in the NVMe PCI timeout path. If device state changes while nvme_poll_irqdisable() is toggling IRQs, the code can act on different IRQ numbers for disable and enable, triggering an "Unbalanced enable" warning and potential availability impact. The issue was published by NVD on 2026-05-08 and later updated on 2026-05-21.

Vendor
Linux
Product
Unknown
CVSS
MEDIUM 4.7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-08
Original CVE updated
2026-05-21
Advisory published
2026-05-08
Advisory updated
2026-05-21

Who should care

Linux kernel maintainers, distribution security teams, and operators running NVMe PCI storage on affected kernel branches should care most. Systems that rely on NVMe timeouts, MSI-X/INTx transitions, or show IRQ-related warnings in logs deserve priority review.

Technical summary

The bug is a race in drivers/nvme/host/pci.c: nvme_poll_irqdisable() calls pci_irq_vector() twice, once before disable_irq() and again before enable_irq(). If nvme_reset_work()/nvme_dev_disable() disables the device in between, pdev->msix_enabled can change and pci_irq_vector() may return a different IRQ number. That can produce an IRQ accounting mismatch and kernel warnings. The fix is to save the IRQ number in a local variable so disable_irq() and enable_irq() operate on the same IRQ, even if IRQ vectors are freed concurrently.

Defensive priority

Medium

Recommended defensive actions

  • Apply the upstream/stable Linux kernel patch referenced in NVD for CVE-2026-43448.
  • Upgrade kernels to versions outside the vulnerable ranges listed by NVD.
  • Review fleet kernel versions against the NVD CPE ranges for 5.7 through 6.19.9, plus 7.0 release candidates.
  • Check affected hosts for IRQ imbalance warnings or NVMe timeout-related kernel log entries.
  • Prioritize systems with NVMe PCI devices and active timeout handling, especially where storage availability is operationally critical.

Evidence notes

The supplied NVD record classifies this as CVSS 4.7 / Medium with AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H and CWE-362. The CVE description states the race between nvme_poll_irqdisable() and nvme_reset_work()/nvme_dev_disable(), and the included crash log shows "Unbalanced enable for IRQ 10" in __enable_irq(). NVD also lists six kernel patch references as remediation evidence. Vulnerable version ranges are taken from the supplied NVD CPE criteria.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-43448 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-43448

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-43448 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-43448

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/265dbc9bc33c29f60f90be3e0afe1c4067ebb70b

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/628773eba024d1107cc9ec157a682cbb42ac912a

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/843e913cef4e33723663a899727f685a95ab53fe

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/b56c49897bdac5cb49e3495ef421c391628ee9bb

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/e311d84c62eb76e025e11a44155b402e55950b83

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/fc71f409b22ca831a9f87a2712eaa09ef2bb4a5e

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.