PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-43496 Linux CVE debrief

CVE-2026-43496 is a Linux kernel networking bug in sch_red that can trigger a kernel panic when red is used with certain child qdiscs, including ones whose peek callback is qdisc_peek_dequeued(). The supplied record describes a failing parent/child dequeue sequence and includes a KASAN null-pointer dereference trace. The fix changes sch_red to use qdisc_dequeue_peeked() after peeking, instead of directly calling the child dequeue path.

Vendor
Linux
Product
Unknown
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-21
Original CVE updated
2026-07-23
Advisory published
2026-05-21
Advisory updated
2026-07-23

Who should care

Linux kernel maintainers, distribution security teams, and operators using traffic-control qdiscs should review this issue, especially deployments that combine sch_red with child qdiscs such as qfq and parent schedulers such as tbf. Any environment relying on kernel packet shaping or queue discipline chaining may be affected if it uses the described pattern.

Technical summary

The issue occurs when sch_red has child qdiscs whose peek() behavior is tied to qdisc_peek_dequeued(). In the described flow, the parent peeks at red, red peeks into its child, and then red incorrectly invokes the child's dequeue() path directly. That can leave the child in an invalid state and leads to a null-pointer dereference/panic in qfq_dequeue(), as shown in the supplied trace. The resolved change replaces the direct dequeue call with qdisc_dequeue_peeked() so the skb is taken from the expected peeked state, including the gso_skb queue path described in the record.

Defensive priority

High for systems using the affected qdisc combinations; the issue can crash the kernel and disrupt networking.

Recommended defensive actions

  • Apply the Linux kernel stable fixes referenced in the official record and backport them to affected branches.
  • Inventory hosts that use sch_red, qfq, tbf, or related traffic-control chains to identify exposure.
  • Test any traffic shaping or QoS configurations that rely on queue discipline chaining after patching.
  • Monitor for kernel panic or KASAN-style crash reports tied to qdisc dequeue paths.
  • If you cannot patch immediately, minimize use of the affected sch_red/qfq/tbf combination in production.

Evidence notes

The supplied CVE description states that sch_red can panic when used with child qdiscs whose peek() callback is qdisc_peek_dequeued(), and it explicitly says the fix is to replace the direct dequeue call with qdisc_dequeue_peeked(). The included crash trace shows a null-ptr-deref in qfq_dequeue() reached via red_dequeue() and tbf_dequeue(). The official NVD record links five Linux kernel stable commit URLs associated with the fix. No CVSS score or vector was provided in the source record.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-43496 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-43496

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-43496 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-43496

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/36aa34f42cb6842cf371f3a2d3e855d24fd57a50

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/458d5615272d3de535748342eb68ca492343048c

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/587dcf970a525f543d8b5855d9f37a4ca97b76ef

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/8d09618840b99ef00154d3e731ce9b11e096196d

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/ce051eede433f876d322ac3550a36a3c6fc4c231

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.