Memory leak in Linux kernel - CVE-2026-43419
Published: May 8, 2026
Vulnerability identifier: #VU130771
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2026-43419
CWE-ID: CWE-401
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vendor: Linux Foundation
Affected software:
Linux kernel
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a memory leak in ceph_mdsc_build_path() when handling error paths. A local user can trigger the vulnerable code path to cause a denial of service.
How to mitigate CVE-2026-43419
Install security update from vendor's repository.
Sources
- https://git.kernel.org/stable/c/040d159a45ded7f33201421a81df0aa2a86e5a0b
- https://git.kernel.org/stable/c/097cd68f46686391a98f2618188f0cb7b7570de2
- https://git.kernel.org/stable/c/13b8b9d6f59ef17fb96c298c3a0d62a8306950cc
- https://git.kernel.org/stable/c/5895d0164c84d7fec6abc198920c257f55c51899
- https://git.kernel.org/stable/c/657dc653b06a3cc0282aea447a3f137fa94066a4