Improper locking in Linux kernel - CVE-2026-43382
Published: May 9, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper lock handling in batadv_v_elp_get_throughput() and batadv_get_real_netdev() when cancelling a delayed work item while the RTNL lock is already held. A local user can trigger the affected code path to cause a denial of service.
The issue can result in a deadlock during ELP metric worker processing for cfg80211 interfaces.
How to mitigate CVE-2026-43382
Sources
- https://git.kernel.org/stable/c/192f40ad8a7dac58dae9199a065dbf7e6e67b75b
- https://git.kernel.org/stable/c/2ab9f2531d37775cd79228c1f5d80e6bd08d11d3
- https://git.kernel.org/stable/c/4c3ae249431b4fcb315d7dfb4c3a13f9e443fd9b
- https://git.kernel.org/stable/c/77808fe7d03ad0062840b95f431869a8b3d88b24
- https://git.kernel.org/stable/c/b7e5d8ddfdf1d6e9e0808d1adf7736a107372d77
- https://git.kernel.org/stable/c/cfc83a3c71517b59c1047db57da31e26a9dc2f33
- https://git.kernel.org/stable/c/f3ca45673dab0514a887231de6f3243a699d5bfd
- https://git.kernel.org/stable/c/fa7b4edfbabdf9235b0ab4bea297fc12b3bec9ca