PatchSiren cyber security CVE debrief
CVE-2026-43470 Linux CVE debrief
CVE-2026-43470 is a Linux kernel NFS flaw that can lead to a kernel oops and denial of service when an NFS create path encounters a directory alias and the error is not handled correctly. The issue was published on 2026-05-08 and updated on 2026-05-21. NVD rates it 5.5 (MEDIUM), and the described impact is availability-only: no confidentiality or integrity impact is identified in the supplied record.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-08
- Original CVE updated
- 2026-05-21
- Advisory published
- 2026-05-08
- Advisory updated
- 2026-05-21
Who should care
Linux kernel maintainers, distro security teams, and operators running affected kernels with NFS client activity should care most. Environments that use concurrent create/delete/open patterns on the same names, especially workloads similar to the observed lustre-racer scenario, should treat this as a priority availability fix.
Technical summary
The source description says nfs3_proc_create could encounter an alias via nfs3_do_create, nfs_add_or_obtain, or d_splice_alias that is actually a directory dentry. In that case, the code previously did not return an error and instead discarded the alias while leaving the original dentry negative. That negative dentry could later reach nfs_atomic_open_v23/finish_open and be passed to do_dentry_open, leading to an oops. The fix is to explicitly check d_is_dir() and return EISDIR so file-opening paths do not proceed on a directory inode. NVD lists affected Linux kernel ranges as 6.10 before 6.12.78, 6.13 before 6.18.19, 6.19 before 6.19.9, and 7.0 release candidates rc1 through rc3.
Defensive priority
Medium
Recommended defensive actions
- Apply the upstream/stable kernel fixes referenced by the four kernel.org patch links in the source record.
- Backport the fix to any supported downstream kernel branches that match the affected version ranges.
- Prioritize patching systems that use NFS heavily or run concurrent create/delete/open workloads on the same paths.
- Validate that your distribution's kernel build includes the directory-alias error handling change before declaring systems remediated.
- Monitor for kernel oopses or crashes in NFS-related paths until patched systems are fully deployed.
Evidence notes
This debrief is based only on the supplied CVE record and NVD metadata. The record describes an NFS create/open handling bug that can cause an oops when a directory alias is mishandled; NVD classifies it with CVSS 3.1 AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H and lists NVD-CWE-noinfo. The supplied record also includes four official kernel.org patch references and affected kernel version ranges.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-43470 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-43470
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-43470 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-43470
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/203c792cb4315360d49973ae2e57feeb6d3dcf7e
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/410666a298c34ebd57256fde6b24c96bd23059a2
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/7e2963773760a664684435201960dd2fb712f1b5
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/9ee1770fcb2f1b48354622b926e7dc10222805f5
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.