Improper control of a resource through its lifetime in Linux kernel - CVE-2026-43054
Published: May 2, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper state management in tcm_loop_target_reset() when handling SCSI target reset recovery. A local user can trigger a reset while commands remain in flight to cause a denial of service.
The issue can leak a LUN reference and cause configfs LUN unlink to hang in D-state.
How to mitigate CVE-2026-43054
Sources
- https://git.kernel.org/stable/c/05ac3754467363558a0a54ae4bb7c89b2c9574cf
- https://git.kernel.org/stable/c/103f79e4949513247d763c6e7f3cbbf62017afdf
- https://git.kernel.org/stable/c/1333eee56cdf3f0cf67c6ab4114c2c9e0a952026
- https://git.kernel.org/stable/c/15f5241d5a52364a7e7867b49128b0442dbcad9d
- https://git.kernel.org/stable/c/757c43c692294cdfad31390accc0e90429b2ef8a
- https://git.kernel.org/stable/c/7cbd69aaa507b1245240a28022bf5da0f07c68d9
- https://git.kernel.org/stable/c/a836054ea81014117ec6b73529a21626a9e1f829