PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-43455 Linux CVE debrief

CVE-2026-43455 is a Linux kernel MCTP routing bug where a missing lock around a check-and-set sequence can race and leak a device reference. The issue is published in NVD with CVSS 5.5 (MEDIUM) and affects multiple kernel release lines until the fixed stable versions. NVD published the record on 2026-05-08 and last modified it on 2026-05-20.

Vendor
Linux
Product
Unknown
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-08
Original CVE updated
2026-05-20
Advisory published
2026-05-08
Advisory updated
2026-05-20

Who should care

Linux kernel maintainers, distro security teams, and operators running kernels that include MCTP support, especially on systems where local users can reach the affected transmit path.

Technical summary

mctp_flow_prepare_output() checks key->dev and may call mctp_dev_set_key() without holding key->lock, even though the related key management functions are annotated as requiring that lock. In the mctp_sendmsg() transmit path, two concurrent callers can both observe key->dev as NULL and each acquire a device reference, but only the final assignment is tracked for release. The result is a lost reference on one device and a resource leak, which primarily impacts availability.

Defensive priority

Medium priority. The flaw requires local access and low privileges, but it can cause a kernel resource leak and availability degradation in affected systems.

Recommended defensive actions

  • Apply the Linux stable fixes referenced in the official kernel patch links.
  • Verify whether your deployed kernel falls within the affected ranges listed by NVD and plan updates accordingly.
  • Prioritize patching systems that use MCTP functionality or expose it to untrusted local users.
  • Monitor for kernel resource exhaustion or unusual device reference growth while remediation is in progress.

Evidence notes

This debrief is based on the supplied NVD CVE record, the CVE timing fields, and the official Linux kernel patch references. The vulnerability description states the race occurs in mctp_flow_prepare_output() when key->dev is checked and set without holding key->lock, and that the consequence is a leaked device reference leading to a resource leak. NVD classifies the issue as CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H and marks affected Linux kernel ranges across multiple stable branches. The record was published on 2026-05-08 and modified on 2026-05-20.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-43455 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-43455

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-43455 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-43455

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/0695712f3a6f1a48915f95767cfb42077683dcdc

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/47893166bc5611ee9a20de6b8d2933b2320fb772

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/7d86aa41c073c4e7eb75fd2e674f1fd8f289728a

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/86f5334fcb48a5b611c33364ab52ca684d0f6d91

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/8d27d9b260dd19c1b519e1a13de6448f9984e30e

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/925a5ffd99cddd7a7e41d5ad120c7a2c6d50260f

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.