Junglewise Threat Intelligence

CVE-2026-43147: Linux Kernel deadlock in PCI/IOV SR-IOV management

CVE-2026-43147 · Severity: medium · CVSS 5.5 · Published 2026-05-06

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's PCI subsystem can cause a system deadlock when managing virtualized network or storage devices. By performing specific hardware configuration commands, a local user could trigger a permanent system freeze, leading to a total loss of availability for the affected server. This impact is particularly relevant for environments using SR-IOV for high-performance virtualization.

Technical details

A deadlock exists in the Linux kernel's PCI/IOV implementation due to recursive acquisition of the 'pci_rescan_remove_lock'. The issue occurs when 'sriov_del_vfs()' is invoked as part of the 'pci_stop_and_remove_bus_device()' path, which already holds the lock. An attacker with local access to sysfs can trigger this by enabling SR-IOV virtual functions and then attempting to remove the physical device. This results in a kernel hang (deadlock). The fix involves reverting the commit that introduced the improper locking mechanism. Patches have been released across multiple stable kernel branches.

Affected products

  • Linux Linux Kernel 5.4.301 to 5.5, 5.10.246 to 5.10.252, 5.15.195 to 5.15.202, 6.1.157 to 6.1.165, 6.6.113 to 6.6.128, 6.12.54 to 6.12.75, 6.17.4 to 6.18.16, 6.19 to 6.19.6

Timeline

  • 2026-05-06: advisory: CVE-2026-43147 published by NVD
  • 2025-12-16: patched: Initial patch authored by Niklas Schnelle

References

Related threats