PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-43499 Linux CVE debrief

CVE-2026-43499 is a Linux kernel synchronization bug in rtmutex handling. The supplied CVE text says remove_waiter() can be reached not only from slowlock paths, but also during proxy-lock rollback from rt_mutex_start_proxy_lock() when invoked by futex_requeue(). In that rollback case, waiter::task is not current, so using current for dequeue-related operations can leave the waiter task’s pi_blocked_on state uncleared, operate without the correct pi_lock held, and feed the wrong task into rt_mutex_adjust_prio_chain(). The fix is to use waiter::task consistently in remove_waiter().

Vendor
Linux
Product
Unknown
CVSS
HIGH 7.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-21
Original CVE updated
2026-09-08
Advisory published
2026-05-21
Advisory updated
2026-09-08

Who should care

Linux kernel maintainers, distro and appliance vendors shipping kernel updates, and operators who rely on futex-heavy or real-time scheduling workloads should pay attention. Security teams responsible for backporting kernel fixes should treat this as a synchronization correctness issue with potential memory-safety consequences.

Technical summary

According to the CVE description, remove_waiter() is used in both slowlock paths and proxy-lock rollback during rt_mutex_start_proxy_lock(). In the rollback case, the waiter being removed is not necessarily the current task. The vulnerable behavior is using current instead of waiter::task for related operations in remove_waiter(), which can: (1) perform the rbtree dequeue without holding waiter::task::pi_lock, (2) fail to clear the waiter task’s pi_blocked_on field, leaving a dangling pointer and possible UAF risk, and (3) cause rt_mutex_adjust_prio_chain() to operate on the wrong top-priority waiter task. The resolved change replaces current with waiter::task in the affected paths.

Defensive priority

High for kernel patching and backporting. This is core locking code in the Linux kernel, and the supplied description explicitly ties it to stale state and dangling-pointer risk. Prioritize any supported kernel branch that includes futex/rtmutex code paths.

Recommended defensive actions

  • Apply the upstream/stable Linux kernel fixes referenced in the record to all supported branches.
  • Backport the change carefully to vendor kernels and long-term support builds that include rtmutex and futex_requeue paths.
  • Validate that remove_waiter() and related priority-inheritance code now operate on waiter::task rather than current in the rollback path.
  • Run regression testing focused on futex, priority inheritance, and real-time mutex workloads after patching.
  • Watch for kernel warnings, oopses, or crashes in code paths involving rt_mutex_start_proxy_lock(), futex_requeue(), pi_blocked_on, and rt_mutex_adjust_prio_chain().

Evidence notes

The supplied CVE text explicitly states that remove_waiter() is used for proxy-lock rollback from rt_mutex_start_proxy_lock() when invoked by futex_requeue(), and that using current there causes three specific problems: missing pi_lock coverage, uncleared pi_blocked_on state, and incorrect rt_mutex_adjust_prio_chain() behavior. The record’s publishedAt/modifiedAt timestamps are 2026-05-21T13:16:19.300Z, NVD vulnStatus is "Received", and the NVD metadata includes five kernel.org stable commit references.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-43499 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-43499

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-43499 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-43499

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/3bfdc63936dd4773109b7b8c280c0f3b5ae7d349

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/3fb7394a837740770f0d6b4b30567e60786a63f2

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/6d52dfcb2a5db86e346cf51f8fcf2071b8085166

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/88614876370aac8ad1050ad785a4c095ba17ac11

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/8a1fc8d698ac5e5916e3082a0f74450d71f9611f

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.