PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-43493 Linux CVE debrief

CVE-2026-43493 is a Linux kernel issue in the pcrypt crypto path. According to the published CVE description, MAY_BACKLOG requests can return EBUSY, and the fix updates pcrypt to handle that case and filter out EINPROGRESS notifications. This reads as a request-handling correctness problem in the kernel crypto subsystem rather than a user-facing application bug.

Vendor
Linux
Product
Unknown
CVSS
CRITICAL 9.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-19
Original CVE updated
2026-06-26
Advisory published
2026-05-19
Advisory updated
2026-06-26

Who should care

Linux kernel maintainers, distro security teams, and operators running systems that rely on the kernel pcrypt crypto subsystem or asynchronous crypto request handling.

Technical summary

The CVE description says pcrypt did not properly handle MAY_BACKLOG requests when they returned EBUSY. The remedy is to explicitly check for EBUSY and suppress EINPROGRESS notifications that should not be treated as successful progress. Based on the source text alone, the issue appears to affect status/notification handling in the kernel crypto request flow and may lead to incorrect completion reporting or failed request processing.

Defensive priority

Moderate. This affects a core Linux kernel crypto path, so kernel updates should be tracked and applied through normal distro maintenance, especially on systems that depend on pcrypt-backed asynchronous crypto operations.

Recommended defensive actions

  • Review whether your kernel branch includes the upstream pcrypt fix referenced by the CVE record.
  • Apply the relevant stable kernel update from your distribution once it contains the correction.
  • If you maintain downstream kernel builds, backport the pcrypt MAY_BACKLOG handling fix into supported branches.
  • Monitor kernel and distro advisories for any follow-on fixes related to the crypto request notification path.

Evidence notes

Evidence is limited to the supplied CVE description and official reference metadata. The CVE text states: 'crypto: pcrypt - Fix handling of MAY_BACKLOG requests' and explains that MAY_BACKLOG requests can return EBUSY, which the fix handles by checking for that value and filtering EINPROGRESS notifications. The NVD record lists official kernel.org stable commit references, supporting that this is an upstream Linux kernel fix. No CVSS score or weakness data was provided in the source corpus.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-43493 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-43493

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-43493 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-43493

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/46271895ddfb1ba41f89f7e0dffbe9c2bcf7380a

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/77d55bc8675ee851ed639dc9be77325a8024cf67

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/915b692e6cb723aac658c25eb82c58fd81235110

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/9f1cbca178c03188e201ed175251372149bb25f2

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/eb34e243df57e32f4c08fa191f3602ea19076276

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.