CVE-2026-43499: high-severity local privilege escalation in the Linux kernel's rtmutex futex-requeue path — patch the vendor kernel and reboot

Asked:
CVE-2026-43499

Five independent official sources cover this CVE — the upstream Linux kernel CVE announcement, Red Hat, Ubuntu, Debian and SUSE — each on its own host, one row per source. Scores are CVSS v3.1 7.8 High and CVSS v4.0 8.5 High; the flaw was introduced in Linux 2.6.39 and published upstream on 2026-05-21. Exploitation in the wild is unconfirmed: none of the five sources states an in-the-wild status.

How the risk works and what stops it

Upstream fixed releases

These are upstream kernel.org releases, not distribution packages. Distributors backport the fix, so never judge a vendor kernel safe or unsafe by its upstream version string alone.

2.6.39flaw introduced (upstream announcement)
6.6.140fixed — 6.6 LTS branch
6.12.86fixed — 6.12 LTS branch
6.18.27fixed — 6.18 branch
7.0.4fixed — 7.0 branch
7.1-rc1fixed — mainline
The upstream announcement names the exact bug — remove_waiter() acting on current instead of waiter::task during proxy-lock rollback — and lists all five fixed releases. lore.kernel.org
Debian ships the fix in package versions per release: bullseye 5.10.262-1 / 6.1.176-1~deb11u1, bookworm 6.1.176-1, trixie 6.12.86-1, unstable 7.0.4-1. security-tracker.debian.org
SUSE published fixed kernel-default, kernel-rt and kmp packages across SLE 12/15 lines in June 2026, scoring both CVSS v3.1 7.8 and v4.0 8.5. suse.com
Ubuntu records publication on 21 May 2026 and a last update on 31 August 2026, tracking upstream commits 8161239 (introduced) and 3bfdc63 (fixed). ubuntu.com
Red Hat describes the flaw as a use-after-free a local attacker could use for elevated privileges or unauthorized code execution. access.redhat.com

Source comparison

SourceSeverity / CVSSRequirementsAffected / fixedDates
lore.kernel.orgintroduced in 2.6.39; fixed in 6.6.140, 6.12.86, 6.18.27, 7.0.4, 7.1-rc12026-05-21
access.redhat.comCVSS v3.1 Base Score: 7.8, Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HAttack Vector: Local, Attack Complexity: Low, Privileges Required: Low, User Interaction: None
ubuntu.comBase score 8.5 · High, Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N, CVSS version: CVSS version:Attack Vector: Local, Attack Complexity: Low, Attack Requirements: None, Privileges Required: Low, User Interaction: Non…linux: introduced by 8161239, fixed by 3bfdc63Publication date 21 May 2026, Last updated 31 August 2026
security-tracker.debian.orgbullseye: 5.10.262-1, 6.1.176-1~deb11u1; bookworm: 6.1.176-1; trixie: 6.12.86-1; (unstable): 7.0.4-1
suse.comBase Score: 7.8 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) / Base Score: 8.5 (CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N…Attack Vector: Local, Attack Complexity: Low, Privileges Required: Low, User Interaction: None / Attack Requirements: No…kernel-default >= 6.4.0-47.1, kernel-default-base >= 6.4.0-47.1.21.24, kernel-default >= 5.14.21-150400.24.222.1, kernel-default >= 5.14.21-150500.55.169.1, ker…published 2026-06-05T16:14:08Z, published 2026-06-05T16:12:36Z, published 2026-0…

Data: 5 result rows, one per official source (Linux kernel CVE announce, Red Hat, Ubuntu, Debian, SUSE), each from its own host and URL; fields cover description, CVSS scores, attack requirements, impacts, affected/fixed versions and dates. CVSS scores are vendor-published base scores. SUSE's long per-package fixed-version list and repeated publish timestamps are truncated for space. Exploitation-in-the-wild status: unconfirmed (not stated by any source). Collected 2026.

This report was generated automatically by Keenable SELECT at a user's request, from publicly available web sources linked herein. Keenable does not review, verify, or endorse its contents and makes no representation as to accuracy, completeness, or timeliness; AI-based extraction may contain errors. Nothing in this report is investment, legal, financial, or other professional advice. All trademarks and referenced content remain the property of their respective owners; no affiliation or endorsement is implied. To report an error, rights concern, or request removal: legal@keenable.ai.

Keenable SELECTAsk your own question
Made with Keenable SELECT