Race condition in Linux kernel - CVE-2026-43226
Published: May 7, 2026
Linux kernel
Linux Foundation
Description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper state management in the RDS/TCP connection handling code when processing connection state transitions. A local user can trigger unexpected state transitions to cause a denial of service.
The issue can leave the shutdown work flag set indefinitely after the connection reaches an invalid state.
Remediation
External links
- https://git.kernel.org/stable/c/19e384a7d00d888303a8285977cdf1970c6cccd6
- https://git.kernel.org/stable/c/81248b1eb3c5954cc1fc7b33b7c03e34d20cb8c8
- https://git.kernel.org/stable/c/899ef00963ce76f9fc421a7d02335fe4ead6389b
- https://git.kernel.org/stable/c/9bcd7c00691a2db9745817d5ea79262a503b135c
- https://git.kernel.org/stable/c/9ff599a9be784a808c36765086e3db2144aa3b66
- https://git.kernel.org/stable/c/a179ac7be8f5a650d0068040705f4cddd6ca369c
- https://git.kernel.org/stable/c/ad22d24be635c6beab6a1fdd3f8b1f3c478d15da
- https://git.kernel.org/stable/c/f0f729bdffb08af32e0f54521b81b8a9e0321f16