LiveActive security incident?Get immediate response
CVE Record

CVE-2026-43071: dcache: Limit the minimal number of bucket to two

In the Linux kernel, the following vulnerability has been resolved: dcache: Limit the minimal number of bucket to two There is an OOB read problem on dentry_hashtable when user sets 'dhash_entries=1': BUG: unable to handle page fault for address: ffff888b30b774b0 #PF: supervisor read access in kernel mode #PF: error_code(0x0000) - not-present page Oops: Oops: 0000 [#1] SMP PTI RIP: 0010:__d_lookup+0x56/0x120 Call Trace: d_lookup.cold+0x16/0x5d lookup_dcache+0x27/0xf0 lookup_one_qstr_excl+0x2a/0x180 start_dirop+0x55/0xa0 simple_start_creating+0x8d/0xa0 debugfs_start_creating+0x8c/0x180 debugfs_create_dir+0x1d/0x1c0 pinctrl_init+0x6d/0x140 do_one_initcall+0x6d/0x3d0 kernel_init_freeable+0x39f/0x460 kernel_init+0x2a/0x260 There will be only one bucket in dentry_hashtable when dhash_entries is set as one, and d_hash_shift is calculated as 32 by dcache_init(). Then, following process will access more than one buckets(which memory region is not allocated) in dentry_hashtable: d_lookup b = d_hash(hash) dentry_hashtable + ((u32)hashlen >> d_hash_shift) // The C standard defines the behavior of right shift amounts // exceeding the bit width of the operand as undefined. The // result of '(u32)hashlen >> d_hash_shift' becomes 'hashlen', // so 'b' will point to an unallocated memory region. hlist_bl_for_each_entry_rcu(b) hlist_bl_first_rcu(head) h->first // read OOB! Fix it by limiting the minimal number of dentry_hashtable bucket to two, so that 'd_hash_shift' won't exceeds the bit width of type u32.

CriticalCVSS 9.1Not KEV-listedUpdated
Glexia's TakeAutomated analysiscritical

Security readout for executives and security teams

Plain-English summary

A Linux kernel dcache flaw can read outside allocated kernel memory when the dentry hash table is configured with only one bucket. The documented failure is a kernel page fault, creating serious availability risk and possible exposure of kernel memory. The supplied record rates it critical, although practical remote reachability is not established by the technical description.

Executive priority

Treat as an urgent verification and patching task because kernel crashes and potential kernel-memory disclosure carry high impact. Prioritize confirmed affected configurations. Current sources do not justify declaring an active internet-wide emergency, because exploitation is not documented and the stated network vector is not reconciled with the configuration prerequisite.

Technical view

Setting dhash_entries=1 creates one dentry hash bucket and causes d_hash_shift to become 32. A 32-bit value is then shifted by 32, producing undefined behavior that can calculate an unallocated bucket address. __d_lookup subsequently performs an out-of-bounds read. The fix enforces a minimum of two buckets.

Likely exposure

Exposure requires an affected Linux kernel and the dhash_entries=1 configuration described by the source. The supplied affected-version data is complex and includes commit identifiers, so determine status through the system's distribution or kernel vendor rather than version-string comparison alone.

Exploitation context

The bundle marks this CVE as absent from KEV and provides no evidence of active exploitation or a public exploit. Although the supplied CVSS vector claims unauthenticated network reachability, the technical description depends on a kernel configuration value. How a remote attacker could establish or exploit that condition is not explained.

Researcher notes

The demonstrated path is d_lookup through d_hash into hlist traversal, ending in an out-of-bounds read from an unallocated hash bucket. Undefined shift behavior is central. Sources demonstrate a kernel fault but do not establish controlled data disclosure, code execution, remote triggerability, or attacker ability to set dhash_entries.

Mitigation direction

  • Apply the distribution or kernel vendor update incorporating the referenced minimum-two-bucket fix.
  • Prioritize systems confirmed to use dhash_entries=1 or otherwise matching vendor-affected builds.
  • Where updating is delayed, remove dhash_entries=1 after approved testing and vendor confirmation.
  • Monitor Linux distribution advisories for precise package and supported-branch remediation details.

Validation and detection

  • Inventory running kernel releases and package builds across Linux systems.
  • Check bootloader and kernel configuration sources for dhash_entries=1.
  • Confirm installed packages contain the applicable referenced stable-kernel fix.
  • Reboot updated systems where required, then verify the running kernel matches the remediated package.
  • Review kernel logs for dcache-related page faults or crashes; absence does not prove safety.
Prepared
Confidence
medium
Sources
9

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2026-43071 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Critical
CVSS
9.1 (3.1)
Known Exploited
No
Published

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

1CVSS vectors
3Timeline events
0ADP providers
8Source links

CVSS vector scores

1 official score

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
9.1CVSS 3.1CriticalCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H3.95.2Linux

Vulnerability scoring details

Base CVSS 3.1 score

9.1Critical
CVSS 3.1 vector shape for CVE-2026-43071Attack VectorAttack ComplexityPrivileges RequiredUser InteractionScopeConfidentiality ImpactIntegrity ImpactAvailability Impact

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Privileges Required
NoneLowHigh
User Interaction
NoneRequired
Scope
ChangedUnchanged
Confidentiality Impact
HighLowNone
Integrity Impact
HighLowNone
Availability Impact
HighLowNone

Vulnerability timeline

Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.

  1. CVE reservedCVE Program

    The CVE ID was reserved by the assigning CNA.

  2. CVE publishedCVE Program

    The CVE record was published.

  3. CVE updatedCVE Program

    The CVE record metadata indicates this as the latest update time.

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
LinuxLinux99d263d4c5b2f541dfacb5391e22e8c91ea982a6, 99d263d4c5b2f541dfacb5391e22e8c91ea982a6, 99d263d4c5b2f541dfacb5391e22e8c91ea982a6, 99d263d4c5b2f541dfacb5391e22e8c91ea982a6, 99d263d4c5b2f541dfacb5391e22e8c91ea982a6, 99d263d4c5b2f541dfacb5391e22e8c91ea982a6, 99d263d4c5b2f541dfacb5391e22e8c91ea982a6, d4c96061fddd129778ce8b70fb093aa532f422d0, be2378cbffe50ce0161f0fdee914adee98af53dc, a8be8af18485f9fade90e1743d940252a39eec84, b5cf3193759f7cd1cfbeef11f5cf067bbce22e55, 3.10.55, 3.12.29, 3.14.19, 3.16.3unaffected
LinuxLinux3.17, 0, 6.1.175, 6.6.136, 6.12.83, 6.18.24, 6.19.14, 7.0.1, 7.1affected
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.