PatchSiren cyber security CVE debrief
CVE-2026-43454 Linux CVE debrief
CVE-2026-43454 is a high-severity Linux kernel issue in netfilter's nf_tables netdev hook handling. According to the published record, duplicate device registration must be avoided when processing NETDEV_REGISTER notifications because the device may already have been added during hook allocation. The CVE was published on 2026-05-08 and later modified on 2026-05-20. NVD rates it as local, low-privilege, no-user-interaction exposure with high confidentiality, integrity, and availability impact.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- HIGH 7.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-08
- Original CVE updated
- 2026-05-20
- Advisory published
- 2026-05-08
- Advisory updated
- 2026-05-20
Who should care
Linux kernel maintainers, distro security teams, and administrators of systems running affected kernel versions should care most. Systems with local users, container workloads, or other paths that expose untrusted local code execution should prioritize review and patching.
Technical summary
NVD lists the vulnerability as affecting Linux kernel versions 6.16 through 6.18.19, 6.19 through 6.19.9, and early 7.0 release candidates (rc1, rc2, rc3). The source description says the fix is in netfilter nf_tables netdev hook handling: when a NETDEV_REGISTER notification arrives, the code must not register the same device twice because nft_netdev_hook_alloc() may already have added it while the hook was being created. The NVD CVSS vector is AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H.
Defensive priority
High. This is a kernel-level issue with local low-privilege exposure and high CIA impact, so affected systems should be patched as soon as vendor updates are available.
Recommended defensive actions
- Apply the vendor or stable-kernel patches referenced by Linux kernel stable commits.
- Verify whether your deployed kernels fall within the affected ranges: 6.16-6.18.19, 6.19-6.19.9, or early 7.0 release candidates.
- Prioritize patching hosts that allow untrusted local users, container tenants, or other local code execution paths.
- Track downstream distro advisories for backported fixes if you do not use upstream stable kernels.
- After patching, confirm the running kernel includes the fix before returning affected systems to normal service.
Evidence notes
All statements are based on the supplied CVE record and NVD metadata. The record identifies the Linux kernel as affected, describes the duplicate-device issue in nf_tables netdev hooks during NETDEV_REGISTER handling, provides affected version ranges, and links three official Linux kernel stable patch references. No exploit details or unsupported root-cause claims are included.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-43454 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-43454
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-43454 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-43454
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/2041cdb078041611510fc189410bc70b29f688fb
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/6d2a95c6890577cc3eab2b20018e16850d7fb094
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/b7cdc5a97d02c943f4bdde4d5767ad0c13cad92b
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.