Improper Check or Handling of Exceptional Conditions in Linux kernel - CVE-2026-43314
Published: May 9, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper timeout handling in the dm driver when processing an injected io-timeout-fail condition on a device-mapper device. A local user can inject a fake timeout and perform read or write operations to cause a denial of service.
Exploitation can leak a request so it is never completed, causing tasks to hang indefinitely.
How to mitigate CVE-2026-43314
Sources
- https://git.kernel.org/stable/c/4f9e7ca933a9fbf9912a384b061a00c77332cbf0
- https://git.kernel.org/stable/c/6cdb21e0c9fdee484feba14fc9e72e9d07daf9f3
- https://git.kernel.org/stable/c/8200fca818c1e2f65bc6cb16d934ff6049302197
- https://git.kernel.org/stable/c/b307b6307f6459841312432bd4bc9519cbac97f5
- https://git.kernel.org/stable/c/c8a23d4c995ef4227bd4de64cd3910637ee6162e
- https://git.kernel.org/stable/c/cf2d06c9fd4b6521ea5b7f73c99c64c2c6f5e224
- https://git.kernel.org/stable/c/ece6720de9403260088209b0b92d45e0b49ff856
- https://git.kernel.org/stable/c/f3a9c95a15d2f4466acad5c68faeff79ca5e9f47