PatchSiren cyber security CVE debrief
CVE-2026-43475 Linux CVE debrief
CVE-2026-43475 affects the Linux kernel storvsc path used by Hyper-V guests. On PREEMPT_RT kernels, the issue can trigger a "scheduling while atomic" warning and a lock-up during storage I/O, creating an availability problem rather than a confidentiality or integrity issue. NVD rates the CVE CVSS 5.5/Medium with low-privilege local attack conditions and high availability impact.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-08
- Original CVE updated
- 2026-05-21
- Advisory published
- 2026-05-08
- Advisory updated
- 2026-05-21
Who should care
Linux kernel maintainers, distro security teams, and operators of Hyper-V guests that run PREEMPT_RT or RT-enabled kernels, especially where storage I/O is sensitive to hangs or lockups.
Technical summary
The CVE description says the storvsc SCSI driver was fixed to address scheduling while atomic on PREEMPT_RT. The provided crash trace shows the failure path involving storvsc_queuecommand, hv_ringbuffer_write, vmbus_sendpacket_mpb_desc, and rt_spin_lock, ending in a kernel splat and lock-up while handling storage activity on Hyper-V. NVD marks multiple kernel branches vulnerable up to the listed fixed release boundaries, indicating the problem spans several maintained kernel lines.
Defensive priority
Medium. Prioritize if you run Linux guests on Hyper-V with PREEMPT_RT or otherwise RT-sensitive kernels; the impact is service disruption and potential guest hangs.
Recommended defensive actions
- Apply the kernel update or backport that includes the storvsc PREEMPT_RT fix for your branch.
- Use the NVD version boundaries as upgrade targets: update past 5.10.253, 5.15.203, 6.1.167, 6.6.130, 6.12.78, 6.18.19, or 6.19.9, depending on the release line you run.
- If you maintain a custom RT kernel, confirm the storvsc patch is present in your downstream tree before deploying.
- After patching, validate Hyper-V guest storage workloads under PREEMPT_RT to confirm the lock-up no longer reproduces.
- Monitor kernel logs for "scheduling while atomic" messages involving hv_storvsc or hv_ringbuffer_write as an operational indicator of the issue.
Evidence notes
The CVE record and NVD detail identify the issue as a Linux kernel storvsc problem on Hyper-V with PREEMPT_RT, and the NVD CVSS vector is AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H. The NVD record also lists affected-version ranges for several kernel branches and provides kernel.org stable patch references as remediation evidence. All timing in this debrief uses the supplied CVE published and modified timestamps; it does not infer issue date from patch publication.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-43475 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-43475
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-43475 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-43475
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/57297736c08233987e5d29ce6584c6ca2a831b12
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/91ab59f76d0866079420ebff1c7959fcd87a242e
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/b82462af23e45e066dd56d2736ea70159a6ad647
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/c2e73d8acd056347a70047e6be7cd98e0e811dfa
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/c7984d196476adcbd51c0ce386d7e90277198d57
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/cf00cb15f2515e38d3b7571bf6800b7c6ce70a84
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/e7919a293f9b6101e38bde0d8613daea6c9955df
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.