Improper handling of exceptional conditions in Linux kernel - CVE-2026-43168
Published: May 7, 2026
Vulnerability identifier: #VU130560
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2026-43168
CWE-ID: CWE-755
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vendor: Linux Foundation
Affected software:
Linux kernel
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper cleanup logic in the ocfs2 reflink xattr entry cleanup code when handling preserved xattr entries. A local user can trigger the flawed cleanup path to cause a denial of service.
How to mitigate CVE-2026-43168
Install security update from vendor's repository.
Sources
- https://git.kernel.org/stable/c/02acc9f72365e50eb45a56b7dacb9114ca3b503c
- https://git.kernel.org/stable/c/2f4daccd9d9b8b2952df7878df8c2e8ba6439398
- https://git.kernel.org/stable/c/3bdc3766aafb052aef4baadef455a84c1c0a059d
- https://git.kernel.org/stable/c/5138c936c2c82c9be8883921854bc6f7e1177d8c
- https://git.kernel.org/stable/c/8ff329353134280b203cb2bce95311cb8f7cbd8a
- https://git.kernel.org/stable/c/b2952dbeac2c3c527cb0519d5ffaeb95b062466a
- https://git.kernel.org/stable/c/bb273b68c1719c2925e05557f7e7099edb066680
- https://git.kernel.org/stable/c/c44d86ca949cb1e5566ad14510cc26fa1a17e2d8