Junglewise Threat Intelligence

CVE-2026-43071: Linux Kernel out-of-bounds read in dcache dentry_hashtable

CVE-2026-43071 · Severity: critical · CVSS 9.1 · Published 2026-05-05

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's directory caching system could allow a system administrator to trigger a kernel crash or potentially access restricted memory. By configuring a specific system parameter (dhash_entries) to an unusually low value, the kernel miscalculates memory offsets, leading to an out-of-bounds memory access. This could result in a complete system failure (Blue Screen/Kernel Panic) or unauthorized access to sensitive kernel data.

Technical details

An out-of-bounds (OOB) read exists in the Linux kernel's dentry_hashtable implementation within fs/dcache.c. When the boot parameter 'dhash_entries' is set to 1, dcache_init() calculates a d_hash_shift value of 32. During a dentry lookup via __d_lookup, the kernel performs a right-shift operation on a 32-bit hash value by the d_hash_shift amount. Under C standards, shifting a 32-bit value by 32 bits is undefined behavior; in this implementation, it results in an incorrect index that points to unallocated memory. An attacker with sufficient privileges to modify kernel boot parameters can trigger this OOB read to cause a kernel oops/denial of service or potentially leak kernel memory. The fix involves enforcing a minimum of two buckets in the dentry_hashtable to ensure d_hash_shift remains within safe bounds.

Affected products

  • Linux Linux Kernel All versions prior to the April 2026 patches

Timeline

  • 2026-01-30: other: Patch submitted by developer
  • 2026-04-22: patched: Commits merged into various stable branches by Greg Kroah-Hartman
  • 2026-05-05: disclosed: CVE published

References

Related threats