PatchSiren cyber security CVE debrief
CVE-2026-43491 Linux CVE debrief
CVE-2026-43491 is a Linux kernel qrtr namespace issue where unbounded NEW_SERVER handling could let a malicious client consume memory by repeatedly adding servers for a node. The kernel fix adds a 256-per-node registration limit, preserves replacement of existing ports, and rate-limits related error messages.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-19
- Original CVE updated
- 2026-08-19
- Advisory published
- 2026-05-19
- Advisory updated
- 2026-08-19
Who should care
Linux kernel maintainers, distro security teams, and operators shipping kernels with qrtr support.
Technical summary
The affected code path in qrtr_ns lacked bound checking on how many servers could be registered per node. According to the CVE description, a malicious client could flood NEW_SERVER messages and exhaust memory. The fix introduces a maximum of 256 server registrations per node, except when the message replaces an existing old port, and also rate-limits error output in qrtr_ns_worker().
Defensive priority
High — memory exhaustion in kernel networking code can destabilize affected systems, so patched kernels should be prioritized.
Recommended defensive actions
- Review whether your Linux kernel builds include qrtr support and track the corresponding stable fixes.
- Apply the upstream kernel update that introduces the per-node 256 registration limit for qrtr ns handling.
- Prioritize rollout on systems that may process untrusted qrtr messages or depend on qrtr-enabled networking components.
- Monitor for abnormal qrtr-related memory growth or repeated NEW_SERVER activity until patching is complete.
- Reduce noisy failure-path logging where possible to help detect genuine anomalies without overwhelming logs.
Evidence notes
Based on the supplied NVD record for CVE-2026-43491, which states that qrtr ns lacked bounds checking on server additions per node and that a malicious client could flood NEW_SERVER messages to exhaust memory. The record also states the fix: limit registrations to 256 per node, allow replacement of old ports, and rate-limit error messages in qrtr_ns_worker(). The NVD entry is marked Received and references five Linux kernel stable commit URLs.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-43491 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-43491
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-43491 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-43491
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/35fb4a0c077c5d1049c2628b769e0a1b1e65df0d
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/3efaad55cad1ded429e3a873bfece389058a526b
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/868202aa2adae427060a42d5bd663b4d782ec02c
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/d5ee2ff98322337951c56398e79d51815acbf955
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/e6f6cd501fb54060940a6eb3f4103eeb5e426ae7
416baaa9-dc9f-4396-8d5f-8c081fb06d67
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.