CVE-2026-43239
Linux kernel SMB client race fix in iface updates.
Is CVE-2026-43239 being exploited?
Not confirmed. CVE-2026-43239 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.35% probability of exploitation in the next 30 days.
How severe is CVE-2026-43239?
CVE-2026-43239 is rated High with a CVSS score of 8.8. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-43239?
Yes. A fix has been recorded for CVE-2026-43239. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-43239 affect?
CVE-2026-43239 affects Linux kernel (SMB client). Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-43239?
Apply patched kernel update; reboot if required
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Possible kernel instability or DoS via concurrent SMB interface updates; local attacker could induce race conditions.
Patch when possible
- affected>= aa45dadd34e44fcd6a9df4b395bee5b5633b4cec and < 93e8e3ee165ae4609a1222b516b573837103d2c3
- affected>= aa45dadd34e44fcd6a9df4b395bee5b5633b4cec and < ab6564f416a6eaf1199200b6100952407b438f7d
- affected>= aa45dadd34e44fcd6a9df4b395bee5b5633b4cec and < 6287eefaf21ec805d42f941bd368018cf397a7f5
- affected>= aa45dadd34e44fcd6a9df4b395bee5b5633b4cec and < 76cc4faba0343c6db945b8dc75425b33d633e1b8
- affected>= aa45dadd34e44fcd6a9df4b395bee5b5633b4cec and < c3c06e42e1527716c54f3ad2ced6a034b5f3a489
- affected5.19
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.