CVE-2026-43071: dcache: Limit the minimal number of bucket to two
In the Linux kernel, the following vulnerability has been resolved:
dcache: Limit the minimal number of bucket to two
There is an OOB read problem on dentry_hashtable when user sets
'dhash_entries=1':
BUG: unable to handle page fault for address: ffff888b30b774b0
#PF: supervisor read access in kernel mode
#PF: error_code(0x0000) - not-present page
Oops: Oops: 0000 [#1] SMP PTI
RIP: 0010:__d_lookup+0x56/0x120
Call Trace:
d_lookup.cold+0x16/0x5d
lookup_dcache+0x27/0xf0
lookup_one_qstr_excl+0x2a/0x180
start_dirop+0x55/0xa0
simple_start_creating+0x8d/0xa0
debugfs_start_creating+0x8c/0x180
debugfs_create_dir+0x1d/0x1c0
pinctrl_init+0x6d/0x140
do_one_initcall+0x6d/0x3d0
kernel_init_freeable+0x39f/0x460
kernel_init+0x2a/0x260
There will be only one bucket in dentry_hashtable when dhash_entries is
set as one, and d_hash_shift is calculated as 32 by dcache_init(). Then,
following process will access more than one buckets(which memory region
is not allocated) in dentry_hashtable:
d_lookup
b = d_hash(hash)
dentry_hashtable + ((u32)hashlen >> d_hash_shift)
// The C standard defines the behavior of right shift amounts
// exceeding the bit width of the operand as undefined. The
// result of '(u32)hashlen >> d_hash_shift' becomes 'hashlen',
// so 'b' will point to an unallocated memory region.
hlist_bl_for_each_entry_rcu(b)
hlist_bl_first_rcu(head)
h->first // read OOB!
Fix it by limiting the minimal number of dentry_hashtable bucket to two,
so that 'd_hash_shift' won't exceeds the bit width of type u32.
Security readout for executives and security teams
Plain-English summary
A Linux kernel dcache flaw can read outside allocated kernel memory when the dentry hash table is configured with only one bucket. The documented failure is a kernel page fault, creating serious availability risk and possible exposure of kernel memory. The supplied record rates it critical, although practical remote reachability is not established by the technical description.
Executive priority
Treat as an urgent verification and patching task because kernel crashes and potential kernel-memory disclosure carry high impact. Prioritize confirmed affected configurations. Current sources do not justify declaring an active internet-wide emergency, because exploitation is not documented and the stated network vector is not reconciled with the configuration prerequisite.
Technical view
Setting dhash_entries=1 creates one dentry hash bucket and causes d_hash_shift to become 32. A 32-bit value is then shifted by 32, producing undefined behavior that can calculate an unallocated bucket address. __d_lookup subsequently performs an out-of-bounds read. The fix enforces a minimum of two buckets.
Likely exposure
Exposure requires an affected Linux kernel and the dhash_entries=1 configuration described by the source. The supplied affected-version data is complex and includes commit identifiers, so determine status through the system's distribution or kernel vendor rather than version-string comparison alone.
Exploitation context
The bundle marks this CVE as absent from KEV and provides no evidence of active exploitation or a public exploit. Although the supplied CVSS vector claims unauthenticated network reachability, the technical description depends on a kernel configuration value. How a remote attacker could establish or exploit that condition is not explained.
Researcher notes
The demonstrated path is d_lookup through d_hash into hlist traversal, ending in an out-of-bounds read from an unallocated hash bucket. Undefined shift behavior is central. Sources demonstrate a kernel fault but do not establish controlled data disclosure, code execution, remote triggerability, or attacker ability to set dhash_entries.
Mitigation direction
Apply the distribution or kernel vendor update incorporating the referenced minimum-two-bucket fix.
Prioritize systems confirmed to use dhash_entries=1 or otherwise matching vendor-affected builds.
Where updating is delayed, remove dhash_entries=1 after approved testing and vendor confirmation.
Monitor Linux distribution advisories for precise package and supported-branch remediation details.
Validation and detection
Inventory running kernel releases and package builds across Linux systems.
Check bootloader and kernel configuration sources for dhash_entries=1.
Confirm installed packages contain the applicable referenced stable-kernel fix.
Reboot updated systems where required, then verify the running kernel matches the remediated package.
Review kernel logs for dcache-related page faults or crashes; absence does not prove safety.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cve · low confidence lookup
CVE-2026-43071 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
1CVSS vectors
3Timeline events
0ADP providers
8Source links
CVSS vector scores
1 official score
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.