Improper Check or Handling of Exceptional Conditions in Linux kernel - CVE-2026-43470
Published: May 8, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper handling of directory aliases in nfs3_proc_create when processing concurrent file creation and removal operations with the same name. A local user can trigger concurrent create and open operations without O_EXCL to cause a denial of service.
The issue can result in a kernel oops when a negative dentry is supplied to do_dentry_open during finish_open.