Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2026-43216

5.5 · MEDIUM
Published May 6, 2026 linux CWE-476 EPSS 0.13% (3th pctl)

Overview

CVE-2026-43216 is a medium-severity vulnerability affecting linux linux_kernel. It was published on May 6, 2026 and has a CVSS 3.1 base score of 5.5 (MEDIUM).

This vulnerability has a CVSS 3.1 base score of 5.5, rated MEDIUM. It requires local or adjacent network access to exploit. Some level of privileges is required for exploitation.

Technical Description

In the Linux kernel, the following vulnerability has been resolved:

net: Drop the lock in skb_may_tx_timestamp()

skb_may_tx_timestamp() may acquire sock::sk_callback_lock. The lock must

not be taken in IRQ context, only softirq is okay. A few drivers receive

the timestamp via a dedicated interrupt and complete the TX timestamp

from that handler. This will lead to a deadlock if the lock is already

write-locked on the same CPU.

Taking the lock can be avoided. The socket (pointed by the skb) will

remain valid until the skb is released. The ->sk_socket and ->file

member will be set to NULL once the user closes the socket which may

happen before the timestamp arrives.

If we happen to observe the pointer while the socket is closing but

before the pointer is set to NULL then we may use it because both

pointer (and the file's cred member) are RCU freed.

Drop the lock. Use READ_ONCE() to obtain the individual pointer. Add a

matching WRITE_ONCE() where the pointer are cleared.

Remediation

Check the references section for vendor advisories and patches from linux. Update linux_kernel to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Affected Products

Vendor Product Versions Status
linux linux_kernel >= 4.0, < 6.18.16 Affected

Frequently Asked Questions

What is CVE-2026-43216?

CVE-2026-43216 is a medium-severity vulnerability affecting linux linux_kernel. It was published on May 6, 2026 and has a CVSS 3.1 base score of 5.5 (MEDIUM).

How severe is CVE-2026-43216?

This vulnerability has a CVSS 3.1 base score of 5.5, rated MEDIUM. It requires local or adjacent network access to exploit. Some level of privileges is required for exploitation.

How do I fix or remediate CVE-2026-43216?

Check the references section for vendor advisories and patches from linux. Update linux_kernel to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2026-43216?

CyberStrike's AI-powered security agents can automatically detect CVE-2026-43216 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.