SB20260508115 - Race condition in Linux kernel ufs core driver
Published: May 8, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Race condition (CVE-ID: CVE-2026-43415)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a race condition in ufshcd_rtc_work() and the UFS suspend path when suspending UFS devices. A local user can trigger UFS suspend while the delayed RTC work is still running to cause a denial of service.
The issue can trigger an asynchronous SError that leads to a kernel panic on affected systems.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/2fcc2fc21cae7a0cbe73053f7fc70680ce2a7f69
- https://git.kernel.org/stable/c/a6a894413b043704b77a6294c379c93b1477e48d
- https://git.kernel.org/stable/c/b0bd84c39289ef6a6c3827dd52c875659291970a
- https://git.kernel.org/stable/c/b17211b512cbf0e07de27e1932428ee6c20df910
- https://git.kernel.org/stable/c/c387a8f1d3713f6b0415ece8485042d0f134b91a