Affects Linux kernel (core infra) across environments; potential kernel crash and local escalation impact.
CVE-2026-43414
Linux kernel qla2xxx fcport double-free vulnerability
Is CVE-2026-43414 being exploited?
Not confirmed. CVE-2026-43414 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.38% probability of exploitation in the next 30 days.
How severe is CVE-2026-43414?
CVE-2026-43414 is rated Critical with a CVSS score of 9.8. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-43414?
Yes. A fix has been recorded for CVE-2026-43414. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-43414 affect?
CVE-2026-43414 affects Linux kernel (qla2xxx driver). Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-43414?
Apply kernel patch with qla2xxx fcport fix
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Local denial-of-service and potential local privilege escalation via fcport double-free in qla2xxx
Patch when possible
- affected>= 4895009c4bb72f71f2e682f1e7d2c2d96e482087 and < d48ea85463f5b34f7b92ea0a13eddf1ab993da7b
- affected>= 4895009c4bb72f71f2e682f1e7d2c2d96e482087 and < c0b7da13a04bd70ef6070bfb9ea85f582294560a
- affected7861213201838480dc222634c56fb6db113d010d
- affected3b9d72442adfbc9ddb0f76dd1b03977b3a578b16
- affectedef23850940d9a52c39936d27254824ccf5e9b6bd
- affected6c6bf6cacf9461f8d301cfac4f9c175d80cbcc63
- affectedcd10dee1f07a782f5aa05703c55299ca86a85ee4
- affectedb03e626bd6d3f0684f56ee1890d70fc9ca991c04
- affected282877633b25d67021a34169c5b5519b1d4ef65e
- affectedf85af9f1aa5e2f53694a6cbe72010f754b5ff862
- affected9b43d2884b54d415caab48878b526dfe2ae9921b
- affected846fb9f112f618ec6ae181d8dae7961652574774
- affected>= 5.15.154 and < 5.16
- affected>= 6.1.84 and < 6.2
- affected>= 6.6.24 and < 6.7
- affected>= 6.7.12 and < 6.8
- affected>= 6.8.3 and < 6.9
- affected6.9
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.