Double free in Linux kernel - CVE-2026-43414

 

Double free in Linux kernel - CVE-2026-43414

Published: May 8, 2026


Vulnerability identifier: #VU130766
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-43414
CWE-ID: CWE-415
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to double free in qla24xx_els_dcmd_iocb() error handling when releasing fcport references. A local user can trigger an error condition to cause a denial of service.


Affected software

Linux kernel
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support
Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support
Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support
Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Ubuntu
Anolis OS
linux-aws (Ubuntu package)
linux (Ubuntu package)
linux-ibm (Ubuntu package)
linux-raspi (Ubuntu package)
linux-kvm (Ubuntu package)
kernel (Red Hat package)
linux-xilinx-zynqmp (Ubuntu package)
linux-gcp-5.15 (Ubuntu package)
linux-oracle-5.15 (Ubuntu package)
linux-azure-fips (Ubuntu package)
bpftool
kernel
kernel-debug
kernel-debug-devel
kernel-devel
kernel-headers
kernel-tools
kernel-tools-libs
kernel-tools-libs-devel
perf
python3-perf
linux-hwe-6.8 (Ubuntu package)
linux-nvidia-tegra (Ubuntu package)
linux-aws-6.8 (Ubuntu package)
linux-azure-fde (Ubuntu package)
linux-azure-fde-6.8 (Ubuntu package)
linux-azure (Ubuntu package)
linux-raspi-realtime (Ubuntu package)
linux-hwe-6.17 (Ubuntu package)
linux-azure-fde-6.17 (Ubuntu package)
linux-azure-6.17 (Ubuntu package)
linux-nvidia-6.17 (Ubuntu package)
linux-oem-6.17 (Ubuntu package)

How to mitigate CVE-2026-43414

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3
linux-aws (Ubuntu package) - addressed in versions 4.4.0-283.317~14.04.1, 4.4.0.1126.128, 4.4.0-1126.133, 4.4.0.1156.153, 4.4.0-1156.162, 4.15.0.1194.192, 4.15.0-1194.207, 4.15.0.2132.126, 4.15.0-2132.138
linux (Ubuntu package) - addressed in versions 4.15.0.253.237, 4.15.0-253.265, 4.15.0.1149.146, 4.15.0-1149.161, 4.15.0.1156.161, 4.15.0-1156.167, 4.15.0.1176.167, 4.15.0-1176.181, 4.15.0.1187.200~16.04.1, 4.15.0-1187.204, 4.15.0.1204.172, 4.15.0-1204.219, 4.15.0.2095.93, 4.15.0-2095.101, 4.15.0.2112.108, 4.15.0-2112.118, 5.4.0.233.225, 5.4.0-233.253, 5.4.0-233.253~18.04.1, 5.4.0-1065.68, 5.4.0.1079.79, 5.4.0-1079.83, 5.4.0.1120.116, 5.4.0-1120.127, 5.4.0.1135.132, 5.4.0-1135.145, 5.4.0.1159.153, 5.4.0-1159.169+fips1, 5.4.0-1159.169~18.04.1, 5.4.0.1161.108, 5.4.0.1161.159, 5.4.0-1161.172, 5.4.0-1161.172+fips1, 5.4.0-1161.172~18.04.1, 5.4.0.1164.106, 5.4.0.1164.166, 5.4.0-1164.173, 5.4.0-1164.173+fips1, 5.4.0-1164.173~18.04.1, 5.4.0.1166.102, 5.4.0.1166.158, 5.4.0-1166.172, 5.4.0-1166.172+fips1, 5.4.0-1166.172~18.04.1, 5.15.0.183.154, 5.15.0-183.193, 5.15.0-183.193~20.04.1, 5.15.0.185.108, 5.15.0.185.166, 5.15.0-185.195+fips1, 5.15.0-185.195~20.04.1, 5.15.0-1052.52, 5.15.0.1052.54, 5.15.0-1063.63, 5.15.0-1063.63~20.04.1, 5.15.0.1094.93, 5.15.0-1094.102, 5.15.0.1103.99, 5.15.0-1103.105, 5.15.0.1103.107, 5.15.0-1103.108, 5.15.0.1105.102, 5.15.0.1105.109, 5.15.0-1105.109~20.04.1, 5.15.0.1106.105, 5.15.0.1106.106, 5.15.0-1106.107, 5.15.0-1106.112, 5.15.0.1107.106, 5.15.0-1107.113, 5.15.0.1108.104, 5.15.0-1108.114, 5.15.0.1110.114, 5.15.0-1110.119, 5.15.0.1111.101, 5.15.0.1111.107, 5.15.0.1111.108, 5.15.0.1111.114, 5.15.0-1111.118, 5.15.0-1111.118+fips1, 5.15.0-1111.118~20.04.1, 5.15.0-1111.121, 5.15.0-1111.121+fips1, 5.15.0.1116.114, 5.15.0-1116.125, 5.15.0-1116.125~20.04.1, 6.8.0-134.134, 6.8.0-1057.58~22.04.1, 6.8.0-1058.61+fips1, 6.8.0-1058.61~22.04.1, 6.8.0-1060.61, 6.8.0-1060.63+fips1, 6.8.0-1060.63~22.04.1, 6.8.0-1063.69, 6.8.0-1063.69+fips1, 6.8.1-1055.56, 6.8.1-1055.56~22.04.1, 6.17.0-40.40
linux-ibm (Ubuntu package) - addressed in versions 5.4.0-1107.112, 5.4.0-1107.112~18.04.1, 5.4.0.1107.136
linux-raspi (Ubuntu package) - addressed in versions 5.4.0-1144.157, 5.4.0-1144.157~18.04.1, 5.4.0.1144.175, 5.15.0.1105.103, 5.15.0-1105.108, 6.8.0-1060.64, 6.17.0-1021.21
linux-kvm (Ubuntu package) - addressed in versions 5.4.0.1148.144, 5.4.0-1148.157
kernel (Red Hat package) - addressed in versions 5.14.0-687.17.1.el9_8, 6.12.0-55.88.1.el10_0, 6.12.0-211.28.1.el10_2
linux-xilinx-zynqmp (Ubuntu package) - addressed in versions 5.15.0.1074.77, 5.15.0-1074.78
linux-gcp-5.15 (Ubuntu package) - addressed in versions 5.15.0-1106.112~20.04.1, 5.15.0-1111.121~20.04.1
linux-oracle-5.15 (Ubuntu package) - update to 5.15.0-1108.114~20.04.1
linux-azure-fips (Ubuntu package) - addressed in versions 5.15.0.1116.101, 5.15.0-1116.125+fips1, 6.8.0-134.134+fips1, 6.8.0-1062.69+fips1
bpftool - update to 6.6.102-6
kernel - update to 6.6.102-6
kernel-debug - update to 6.6.102-6
kernel-debug-devel - update to 6.6.102-6
kernel-devel - update to 6.6.102-6
kernel-headers - update to 6.6.102-6
kernel-tools - update to 6.6.102-6
kernel-tools-libs - update to 6.6.102-6
kernel-tools-libs-devel - update to 6.6.102-6
perf - update to 6.6.102-6
python3-perf - update to 6.6.102-6
linux-hwe-6.8 (Ubuntu package) - update to 6.8.0-136.136~22.04.1
linux-nvidia-tegra (Ubuntu package) - update to 6.8.0-1029.30
linux-aws-6.8 (Ubuntu package) - addressed in versions 6.8.0-1045.48, 6.8.0-1057.58~22.04.1, 6.8.0-1058.61.1, 6.8.0-1058.64, 6.8.0-1060.61~22.04.1, 6.8.0-1060.63~22.04.1, 6.8.0-1063.69~22.04.1
linux-azure-fde (Ubuntu package) - update to 6.8.0-1062.69
linux-azure-fde-6.8 (Ubuntu package) - update to 6.8.0-1062.69~22.04.1
linux-azure (Ubuntu package) - addressed in versions 6.8.0-1063.71, 6.8.0-1063.71~22.04.1
linux-raspi-realtime (Ubuntu package) - update to 6.8.0-2049.50
linux-hwe-6.17 (Ubuntu package) - update to 6.17.0-40.40~24.04.1
linux-azure-fde-6.17 (Ubuntu package) - update to 6.17.0-1018.18~24.04.1
linux-azure-6.17 (Ubuntu package) - update to 6.17.0-1021.21~24.04.1
linux-nvidia-6.17 (Ubuntu package) - update to 6.17.0-1026.26
linux-oem-6.17 (Ubuntu package) - update to 6.17.0-1028.28

External References

Related Security Bulletins