Junglewise Threat Intelligence

CVE-2026-43239: Linux Kernel race condition in SMB client query_interfaces

CVE-2026-43239 · Severity: high · CVSS 8.8 · Published 2026-05-06

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A race condition vulnerability was identified in the Linux kernel's SMB client, which handles connections to network file shares. This flaw could allow multiple processes to simultaneously update network interface information, potentially leading to system instability or unauthorized data access. In a business environment, this could disrupt access to shared files or compromise the integrity of data stored on network servers.

Technical details

A race condition exists in the Linux kernel SMB client within the 'query_interfaces' function. The vulnerability is caused by a lack of proper synchronization when updating the 'iface_last_update' field, allowing two concurrent threads to attempt to update network interfaces simultaneously. An attacker could potentially exploit this race condition to cause memory corruption or a denial-of-service state. The fix involves moving the check and update of 'iface_last_update' inside the 'iface_lock' spinlock to ensure atomicity. Patches have been released for various stable kernel branches including 6.6.y, 6.12.y, 6.18.y, and 6.19.y.

Affected products

  • Linux Linux Kernel 5.19.1 to 6.6.128, 6.7 to 6.12.75, 6.13 to 6.18.16, 6.19 to 6.19.6

Timeline

  • 2026-05-06: advisory: Initial disclosure of CVE-2026-43239
  • 2026-05-06: disclosed
  • 2026-01-19: patched: Patch authored by Henrique Carvalho

References

Related threats