PatchSiren cyber security CVE debrief
CVE-2026-43499 Linux CVE debrief
CVE-2026-43499 is a Linux kernel synchronization bug in rtmutex handling. The supplied CVE text says remove_waiter() can be reached not only from slowlock paths, but also during proxy-lock rollback from rt_mutex_start_proxy_lock() when invoked by futex_requeue(). In that rollback case, waiter::task is not current, so using current for dequeue-related operations can leave the waiter task’s pi_blocked_on state uncleared, operate without the correct pi_lock held, and feed the wrong task into rt_mutex_adjust_prio_chain(). The fix is to use waiter::task consistently in remove_waiter().
- Vendor
- Linux
- Product
- Unknown
- CVSS
- HIGH 7.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-21
- Original CVE updated
- 2026-09-08
- Advisory published
- 2026-05-21
- Advisory updated
- 2026-09-08
Who should care
Linux kernel maintainers, distro and appliance vendors shipping kernel updates, and operators who rely on futex-heavy or real-time scheduling workloads should pay attention. Security teams responsible for backporting kernel fixes should treat this as a synchronization correctness issue with potential memory-safety consequences.
Technical summary
According to the CVE description, remove_waiter() is used in both slowlock paths and proxy-lock rollback during rt_mutex_start_proxy_lock(). In the rollback case, the waiter being removed is not necessarily the current task. The vulnerable behavior is using current instead of waiter::task for related operations in remove_waiter(), which can: (1) perform the rbtree dequeue without holding waiter::task::pi_lock, (2) fail to clear the waiter task’s pi_blocked_on field, leaving a dangling pointer and possible UAF risk, and (3) cause rt_mutex_adjust_prio_chain() to operate on the wrong top-priority waiter task. The resolved change replaces current with waiter::task in the affected paths.
Defensive priority
High for kernel patching and backporting. This is core locking code in the Linux kernel, and the supplied description explicitly ties it to stale state and dangling-pointer risk. Prioritize any supported kernel branch that includes futex/rtmutex code paths.
Recommended defensive actions
- Apply the upstream/stable Linux kernel fixes referenced in the record to all supported branches.
- Backport the change carefully to vendor kernels and long-term support builds that include rtmutex and futex_requeue paths.
- Validate that remove_waiter() and related priority-inheritance code now operate on waiter::task rather than current in the rollback path.
- Run regression testing focused on futex, priority inheritance, and real-time mutex workloads after patching.
- Watch for kernel warnings, oopses, or crashes in code paths involving rt_mutex_start_proxy_lock(), futex_requeue(), pi_blocked_on, and rt_mutex_adjust_prio_chain().
Evidence notes
The supplied CVE text explicitly states that remove_waiter() is used for proxy-lock rollback from rt_mutex_start_proxy_lock() when invoked by futex_requeue(), and that using current there causes three specific problems: missing pi_lock coverage, uncleared pi_blocked_on state, and incorrect rt_mutex_adjust_prio_chain() behavior. The record’s publishedAt/modifiedAt timestamps are 2026-05-21T13:16:19.300Z, NVD vulnStatus is "Received", and the NVD metadata includes five kernel.org stable commit references.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-43499 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-43499
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-43499 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-43499
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/3bfdc63936dd4773109b7b8c280c0f3b5ae7d349
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/3fb7394a837740770f0d6b4b30567e60786a63f2
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/6d52dfcb2a5db86e346cf51f8fcf2071b8085166
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/88614876370aac8ad1050ad785a4c095ba17ac11
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/8a1fc8d698ac5e5916e3082a0f74450d71f9611f
416baaa9-dc9f-4396-8d5f-8c081fb06d67
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.