CVE-2026-43216Patch(linux / linux_kernel)

LOWCVSS 5.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch linux linux_kernel systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In the Linux kernel, the following vulnerability has been resolved: net: Drop the lock in skb_may_tx_timestamp() skb_may_tx_timestamp() may acquire sock::sk_callback_lock. The lock must not be taken in IRQ context, only softirq is okay. A few drivers receive the timestamp via a dedicated interrupt and complete the TX timestamp from that handler. This will lead to a deadlock if the lock is already write-locked on the same CPU. Taking the lock can be avoided. The socket (pointed by the skb) will remain valid until the skb is released. The ->sk_socket and ->file member will be set to NULL once the user closes the socket which may happen before the timestamp arrives. If we happen to observe the pointer while the socket is closing but before the pointer is set to NULL then we may use it because both pointer (and the file's cred member) are RCU freed. Drop the lock. Use READ_ONCE() to obtain the individual pointer. Add a matching WRITE_ONCE() where the pointer are cleared.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-476

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • linux_kernel

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
linux_kernel

1 version affected across 1 product

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-05-07: 1Patch / Workaround · 2026-05-07: 1Technical Details · 2026-05-07: 105-07
Signal classification1 categories
Patch
1100.0%
Referenced assets1 URL
Full discourse1 post
  • WindowsForum@windowsforum
    Patch

    🪛 Linux networking “deadlock” CVE: thrilling name, boring fix—just removing an unsafe lock acquisition. But that’s the point: reliability flaws become security headaches when systems freeze under load. #Windows #Security https://windowsforum.com/threads/cve-2026-43216-linux-networking-deadlock-fix-impact-and-patch-priorities.416777/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #PatchManagement #LinuxKernel https://t.co/CupuaJyQWS

    Post summary

    The post highlights the discovery of a deadlock vulnerability (CVE‑2026‑43216) in Linux networking and underscores the release of a patch that removes an unsafe lock acquisition.

    0000043
    1.1K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
OSlinuxlinux_kernel---
OSlinuxlinux_kernel7.0--

Explore more