Junglewise Threat Intelligence

CVE-2026-43489: Linux Kernel liveupdate state inconsistency in luo_file

CVE-2026-43489 · Severity: info · CVSS 0 · Published 2026-05-13

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's live update mechanism could allow a local user to cause system instability or crashes. The issue occurs when the system fails to properly track failed attempts to recover files during a live update, potentially leading the kernel to access memory that has already been freed. This could disrupt system operations or lead to a denial of service during maintenance windows.

Technical details

A vulnerability exists in the Linux kernel's live update (LUO) mechanism within `kernel/liveupdate/luo_file.c`. The `luo_file` structure previously used a boolean to track successful file retrievals but failed to record when a retrieval attempt failed. If a `LIVEUPDATE_SESSION_RETRIEVE_FD` ioctl fails mid-operation (e.g., during folio restoration), subsequent retry attempts or the `finish()` callback may attempt to access or free serialized data structures that were already partially processed or freed. This state inconsistency can trigger kernel warnings or memory corruption. The fix replaces the boolean with an integer status code to explicitly track success, failure, and the specific error encountered, preventing unsafe retries.

Affected products

  • Linux Linux Kernel Fixed in 1d3ad69 and f85b1c6

Timeline

  • 2026-02-16: patched: Initial patch authored by Google
  • 2026-05-13: disclosed: CVE published

References

Related threats