PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-43491 Linux CVE debrief

CVE-2026-43491 is a Linux kernel qrtr namespace issue where unbounded NEW_SERVER handling could let a malicious client consume memory by repeatedly adding servers for a node. The kernel fix adds a 256-per-node registration limit, preserves replacement of existing ports, and rate-limits related error messages.

Vendor
Linux
Product
Unknown
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-19
Original CVE updated
2026-08-19
Advisory published
2026-05-19
Advisory updated
2026-08-19

Who should care

Linux kernel maintainers, distro security teams, and operators shipping kernels with qrtr support.

Technical summary

The affected code path in qrtr_ns lacked bound checking on how many servers could be registered per node. According to the CVE description, a malicious client could flood NEW_SERVER messages and exhaust memory. The fix introduces a maximum of 256 server registrations per node, except when the message replaces an existing old port, and also rate-limits error output in qrtr_ns_worker().

Defensive priority

High — memory exhaustion in kernel networking code can destabilize affected systems, so patched kernels should be prioritized.

Recommended defensive actions

  • Review whether your Linux kernel builds include qrtr support and track the corresponding stable fixes.
  • Apply the upstream kernel update that introduces the per-node 256 registration limit for qrtr ns handling.
  • Prioritize rollout on systems that may process untrusted qrtr messages or depend on qrtr-enabled networking components.
  • Monitor for abnormal qrtr-related memory growth or repeated NEW_SERVER activity until patching is complete.
  • Reduce noisy failure-path logging where possible to help detect genuine anomalies without overwhelming logs.

Evidence notes

Based on the supplied NVD record for CVE-2026-43491, which states that qrtr ns lacked bounds checking on server additions per node and that a malicious client could flood NEW_SERVER messages to exhaust memory. The record also states the fix: limit registrations to 256 per node, allow replacement of old ports, and rate-limit error messages in qrtr_ns_worker(). The NVD entry is marked Received and references five Linux kernel stable commit URLs.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-43491 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-43491

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-43491 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-43491

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/35fb4a0c077c5d1049c2628b769e0a1b1e65df0d

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/3efaad55cad1ded429e3a873bfece389058a526b

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/868202aa2adae427060a42d5bd663b4d782ec02c

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/d5ee2ff98322337951c56398e79d51815acbf955

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/e6f6cd501fb54060940a6eb3f4103eeb5e426ae7

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.