Improper locking in Linux kernel - CVE-2026-43475
Published: May 8, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper locking in storvsc_queuecommand in the hv_storvsc driver when processing SCSI I/O on systems with PREEMPT_RT enabled. A local user can trigger crafted I/O activity to cause a denial of service.
Exploitation requires a Linux guest running on Hyper-V with PREEMPT_RT enabled.
How to mitigate CVE-2026-43475
Sources
- https://git.kernel.org/stable/c/57297736c08233987e5d29ce6584c6ca2a831b12
- https://git.kernel.org/stable/c/91ab59f76d0866079420ebff1c7959fcd87a242e
- https://git.kernel.org/stable/c/b82462af23e45e066dd56d2736ea70159a6ad647
- https://git.kernel.org/stable/c/c2e73d8acd056347a70047e6be7cd98e0e811dfa
- https://git.kernel.org/stable/c/c7984d196476adcbd51c0ce386d7e90277198d57
- https://git.kernel.org/stable/c/cf00cb15f2515e38d3b7571bf6800b7c6ce70a84
- https://git.kernel.org/stable/c/e7919a293f9b6101e38bde0d8613daea6c9955df
- https://git.kernel.org/stable/c/f8db760f4f52a73a022a3d6c84c488ead952a9b5