Race condition in Linux kernel - CVE-2026-43275
Published: May 7, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a race condition in the ufs core driver exception event handling work when suspending the system with the runtime power management level set to UFS_PM_LVL_0. A local user can trigger suspend while exception handling work is pending to cause a denial of service.
The issue occurs because the device power mode and link state remain active at this power management level, allowing exception handling to access the host controller after the system has entered a deep power-down state.
How to mitigate CVE-2026-43275
Sources
- https://git.kernel.org/stable/c/5d186731bc335cc049d4e57ab9f563cfab95593e
- https://git.kernel.org/stable/c/78d8e2d6352e8317686ee3a44811ac14c415a57d
- https://git.kernel.org/stable/c/aa8d68d97c7f0ef966e51afc17fdbdc372700edf
- https://git.kernel.org/stable/c/aac2fee7513dd25042a616f86a1469b4858d2c5c
- https://git.kernel.org/stable/c/ab71c146c135f9af1614ef0fc29a0a3b84f1a373
- https://git.kernel.org/stable/c/d5c3a1a13f97355c397f9439d79cb04b182958a3
- https://git.kernel.org/stable/c/f8ef441811ec413717f188f63d99182f30f0f08e