CVE-2026-43071Disclosure(linux / linux_kernel)

LOWCVSS 9.1 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch linux linux_kernel systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In the Linux kernel, the following vulnerability has been resolved: dcache: Limit the minimal number of bucket to two There is an OOB read problem on dentry_hashtable when user sets 'dhash_entries=1': BUG: unable to handle page fault for address: ffff888b30b774b0 #PF: supervisor read access in kernel mode #PF: error_code(0x0000) - not-present page Oops: Oops: 0000 [#1] SMP PTI RIP: 0010:__d_lookup+0x56/0x120 Call Trace: d_lookup.cold+0x16/0x5d lookup_dcache+0x27/0xf0 lookup_one_qstr_excl+0x2a/0x180 start_dirop+0x55/0xa0 simple_start_creating+0x8d/0xa0 debugfs_start_creating+0x8c/0x180 debugfs_create_dir+0x1d/0x1c0 pinctrl_init+0x6d/0x140 do_one_initcall+0x6d/0x3d0 kernel_init_freeable+0x39f/0x460 kernel_init+0x2a/0x260 There will be only one bucket in dentry_hashtable when dhash_entries is set as one, and d_hash_shift is calculated as 32 by dcache_init(). Then, following process will access more than one buckets(which memory region is not allocated) in dentry_hashtable: d_lookup b = d_hash(hash) dentry_hashtable + ((u32)hashlen >> d_hash_shift) // The C standard defines the behavior of right shift amounts // exceeding the bit width of the operand as undefined. The // result of '(u32)hashlen >> d_hash_shift' becomes 'hashlen', // so 'b' will point to an unallocated memory region. hlist_bl_for_each_entry_rcu(b) hlist_bl_first_rcu(head) h->first // read OOB! Fix it by limiting the minimal number of dentry_hashtable bucket to two, so that 'd_hash_shift' won't exceeds the bit width of type u32.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-125

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • linux_kernel

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-05-13)
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
linux_kernel

1 version affected across 1 product

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-05-05: 1Mentions · 2026-05-13: 2Patch / Workaround · 2026-05-13: 1Technical Details · 2026-05-05: 1Technical Details · 2026-05-13: 205-0505-13
Signal classification3 categories
Disclosure
133.3%
General
133.3%
Patch
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-05-051
Disclosure1
2026-05-132
General1Patch1
Full discourse3 posts
  • Brad Spengler@spendergrsec
    Disclosure

    And to make sure you know it's important, they also published a CVE for this: https://lore.kernel.org/linux-cve-announce/2026050557-CVE-2026-43071-9e21@gregkh/T/#u A "vulnerability" that exists only when you provide dhash_entries=1 on the kernel commandline, resulting in a crash of the kernel at boot.

    Post summary

    The post announces CVE-2026-43071, a kernel crash caused by setting dhash_entries=1 on the command line, but does not mention any PoC, exploit, active use, or remediation.

    1111122.7K
    6.9K followersView on X
  • Lyrie.ai@lyrie_ai
    General

    Unpopular opinion: The cybersecurity industry is selling you dashboards. CVE: CVE-2026-43071 CVSS: 9.1 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The post briefly announces a new critical CVE (CVE-2026-43071) with a CVSS v3.1 rating of 9.1 but provides no evidence of evidence of exploitation, PoC, or mitigation steps.

    1001036
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Patch

    https://lyrie.ai/research/research/cve-2026-43071-advisory #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The Lyrie AI advisory for CVE‑2026‑43071 presents technical details and a patch or mitigation step, but does not provide a PoC, exploit code, or evidence of active exploitation.

    0001028
    210 followersView on X
CPE platform detail5 entries

5 of 5 entries

PartVendorProductVersionTarget SWTarget HW
OSlinuxlinux_kernel---
OSlinuxlinux_kernel3.17--
OSlinuxlinux_kernel3.17--
OSlinuxlinux_kernel3.17--
OSlinuxlinux_kernel3.17--

Explore more