Race condition in Linux kernel - CVE-2026-43415
Published: May 8, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a race condition in ufshcd_rtc_work() and the UFS suspend path when suspending UFS devices. A local user can trigger UFS suspend while the delayed RTC work is still running to cause a denial of service.
The issue can trigger an asynchronous SError that leads to a kernel panic on affected systems.
How to mitigate CVE-2026-43415
Sources
- https://git.kernel.org/stable/c/2fcc2fc21cae7a0cbe73053f7fc70680ce2a7f69
- https://git.kernel.org/stable/c/a6a894413b043704b77a6294c379c93b1477e48d
- https://git.kernel.org/stable/c/b0bd84c39289ef6a6c3827dd52c875659291970a
- https://git.kernel.org/stable/c/b17211b512cbf0e07de27e1932428ee6c20df910
- https://git.kernel.org/stable/c/c387a8f1d3713f6b0415ece8485042d0f134b91a