Improper locking in Linux kernel - CVE-2026-43115
Published: May 7, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper locking in tiny SRCU when starting a grace period from call_srcu() while a scheduler lock is held. A local user can trigger call_srcu() in this state to cause a denial of service.
A use-after-free may also occur if queued irq_work executes after SRCU structure cleanup begins.