Affects Linux kernel, core infrastructure used broadly; high risk of local privilege escalation on many systems.
CVE-2026-43071
Linux kernel OOB read in dentry_hashtable when dhash_entries=1.
Is CVE-2026-43071 being exploited?
Not confirmed. CVE-2026-43071 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.40% probability of exploitation in the next 30 days.
How severe is CVE-2026-43071?
CVE-2026-43071 is rated Critical with a CVSS score of 9.1. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-43071?
Yes. A fix has been recorded for CVE-2026-43071. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-43071 affect?
CVE-2026-43071 affects Linux kernel (all supported versions). Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-43071?
Upgrade to patched kernel version
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Local privilege escalation via kernel OOB read; potential memory corruption/crash.
Immediate action required
- affected>= 99d263d4c5b2f541dfacb5391e22e8c91ea982a6 and < 45b06bb5ea96f75ad81d7ef446f832ea6b0026fe
- affected>= 99d263d4c5b2f541dfacb5391e22e8c91ea982a6 and < 426ef05e82ee52c8d0e95fc0808b7383d8352d73
- affected>= 99d263d4c5b2f541dfacb5391e22e8c91ea982a6 and < ddd57ebce245f9c7e2f6902a6c087d6186d2385d
- affected>= 99d263d4c5b2f541dfacb5391e22e8c91ea982a6 and < 755b40903eff563768d4d96fd4ef51ec48adde3b
- affected>= 99d263d4c5b2f541dfacb5391e22e8c91ea982a6 and < 5718df131ab78897a9dd1f2e71c3ba732d4392af
- affected>= 99d263d4c5b2f541dfacb5391e22e8c91ea982a6 and < 277cedabb0ab86baae83fa58218be13c6d3e5526
- affected>= 99d263d4c5b2f541dfacb5391e22e8c91ea982a6 and < f08fe8891c3eeb63b73f9f1f6d97aa629c821579
- affectedd4c96061fddd129778ce8b70fb093aa532f422d0
- affectedbe2378cbffe50ce0161f0fdee914adee98af53dc
- affecteda8be8af18485f9fade90e1743d940252a39eec84
- affectedb5cf3193759f7cd1cfbeef11f5cf067bbce22e55
- affected>= 3.10.55 and < 3.11
- affected>= 3.12.29 and < 3.13
- affected>= 3.14.19 and < 3.15
- affected>= 3.16.3 and < 3.17
- affected3.17
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.