CVE-2026-43215

Updated on 06 May 2026

Severity

8.8 High severity

Details

CVSS score
8.8

Overview

About vulnerability

In the Linux kernel, the following vulnerability has been resolved: cifs: Fix locking usage for tcon fields We used to use the cifs_tcp_ses_lock to protect a lot of objects that are not just the server, ses or tcon lists. We later introduced srv_lock, ses_lock and tc_lock to protect fields within the corresponding structs. This was done to provide a more granular protection and avoid unnecessary serialization. There were still a couple of uses of cifs_tcp_ses_lock to provide tcon fields. In this patch, I’ve replaced them with tc_lock. A flaw was found in the Linux kernel’s Common Internet File System (CIFS) implementation. Incorrect locking mechanisms were used for tcon fields, where the cifs_tcp_ses_lock was applied too broadly instead of more granular locks. This improper locking could lead to concurrency issues within the kernel, potentially resulting in system instability or a denial of service (DoS).

Details

KernelCare state

Live-patch status from KernelCare for each operating system.

Operating system Status Covered kernels
Debian 13 Planned
Ubuntu 24.04 Planned
Ubuntu 24.04 AWS Planned