PatchSiren cyber security CVE debrief
CVE-2026-43493 Linux CVE debrief
CVE-2026-43493 is a Linux kernel issue in the pcrypt crypto path. According to the published CVE description, MAY_BACKLOG requests can return EBUSY, and the fix updates pcrypt to handle that case and filter out EINPROGRESS notifications. This reads as a request-handling correctness problem in the kernel crypto subsystem rather than a user-facing application bug.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-19
- Original CVE updated
- 2026-06-26
- Advisory published
- 2026-05-19
- Advisory updated
- 2026-06-26
Who should care
Linux kernel maintainers, distro security teams, and operators running systems that rely on the kernel pcrypt crypto subsystem or asynchronous crypto request handling.
Technical summary
The CVE description says pcrypt did not properly handle MAY_BACKLOG requests when they returned EBUSY. The remedy is to explicitly check for EBUSY and suppress EINPROGRESS notifications that should not be treated as successful progress. Based on the source text alone, the issue appears to affect status/notification handling in the kernel crypto request flow and may lead to incorrect completion reporting or failed request processing.
Defensive priority
Moderate. This affects a core Linux kernel crypto path, so kernel updates should be tracked and applied through normal distro maintenance, especially on systems that depend on pcrypt-backed asynchronous crypto operations.
Recommended defensive actions
- Review whether your kernel branch includes the upstream pcrypt fix referenced by the CVE record.
- Apply the relevant stable kernel update from your distribution once it contains the correction.
- If you maintain downstream kernel builds, backport the pcrypt MAY_BACKLOG handling fix into supported branches.
- Monitor kernel and distro advisories for any follow-on fixes related to the crypto request notification path.
Evidence notes
Evidence is limited to the supplied CVE description and official reference metadata. The CVE text states: 'crypto: pcrypt - Fix handling of MAY_BACKLOG requests' and explains that MAY_BACKLOG requests can return EBUSY, which the fix handles by checking for that value and filtering EINPROGRESS notifications. The NVD record lists official kernel.org stable commit references, supporting that this is an upstream Linux kernel fix. No CVSS score or weakness data was provided in the source corpus.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-43493 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-43493
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-43493 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-43493
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/46271895ddfb1ba41f89f7e0dffbe9c2bcf7380a
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/77d55bc8675ee851ed639dc9be77325a8024cf67
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/915b692e6cb723aac658c25eb82c58fd81235110
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/9f1cbca178c03188e201ed175251372149bb25f2
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/eb34e243df57e32f4c08fa191f3602ea19076276
416baaa9-dc9f-4396-8d5f-8c081fb06d67
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.