Use-after-free in Linux kernel - CVE-2026-43379
Published: May 8, 2026
Vulnerability identifier: #VU130797
CSH Severity: Low
CVSS v4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-43379
CWE-ID: CWE-416
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in smb_lazy_parent_lease_break_close() when handling concurrent lease break close operations. A local user can trigger a race condition to cause a denial of service.
Affected software
Linux kernel
Anolis OS
bpftool
kernel
kernel-debug
kernel-debug-devel
kernel-devel
kernel-headers
kernel-tools
kernel-tools-libs
kernel-tools-libs-devel
perf
python3-perf
Anolis OS
bpftool
kernel
kernel-debug
kernel-debug-devel
kernel-devel
kernel-headers
kernel-tools
kernel-tools-libs
kernel-tools-libs-devel
perf
python3-perf
How to mitigate CVE-2026-43379
Install security update from vendor's repository.
Linux kernel - update to 7.0 rc3
bpftool - update to 6.6.102-6
kernel - update to 6.6.102-6
kernel-debug - update to 6.6.102-6
kernel-debug-devel - update to 6.6.102-6
kernel-devel - update to 6.6.102-6
kernel-headers - update to 6.6.102-6
kernel-tools - update to 6.6.102-6
kernel-tools-libs - update to 6.6.102-6
kernel-tools-libs-devel - update to 6.6.102-6
perf - update to 6.6.102-6
python3-perf - update to 6.6.102-6
bpftool - update to 6.6.102-6
kernel - update to 6.6.102-6
kernel-debug - update to 6.6.102-6
kernel-debug-devel - update to 6.6.102-6
kernel-devel - update to 6.6.102-6
kernel-headers - update to 6.6.102-6
kernel-tools - update to 6.6.102-6
kernel-tools-libs - update to 6.6.102-6
kernel-tools-libs-devel - update to 6.6.102-6
perf - update to 6.6.102-6
python3-perf - update to 6.6.102-6
External References
- https://git.kernel.org/stable/c/960699317d39f46611f4ebeb69edc567c1f4e6b6
- https://git.kernel.org/stable/c/b3568347c51c46e2cabc356bc34676df98296619
- https://git.kernel.org/stable/c/bf4d66d72e4a9e268c1012c331ce9eaedb5e2086
- https://git.kernel.org/stable/c/dbbd328cf58261ca239756fe1c0d10c9518d3399
- https://git.kernel.org/stable/c/eac3361e3d5dd8067b3258c69615888eb45e9f25