cbcvebase.
CVE-2026-43239
published 2026-05-06

CVE-2026-43239: In the Linux kernel, the following vulnerability has been resolved: smb: client: prevent races in ->query_interfaces() It was possible for two query interface…

PriorityP343high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
0.35%
28.1th percentile
In the Linux kernel, the following vulnerability has been resolved: smb: client: prevent races in ->query_interfaces() It was possible for two query interface works to be concurrently trying to update the interfaces. Prevent this by checking and updating iface_last_update under iface_lock.

Affected

43 ranges· showing 25
VendorProductVersion rangeFixed in
linuxlinux
linuxlinux>= aa45dadd34e44fcd6a9df4b395bee5b5633b4cec < 93e8e3ee165ae4609a1222b516b573837103d2c393e8e3ee165ae4609a1222b516b573837103d2c3
linuxlinux>= aa45dadd34e44fcd6a9df4b395bee5b5633b4cec < ab6564f416a6eaf1199200b6100952407b438f7dab6564f416a6eaf1199200b6100952407b438f7d
linuxlinux>= aa45dadd34e44fcd6a9df4b395bee5b5633b4cec < 6287eefaf21ec805d42f941bd368018cf397a7f56287eefaf21ec805d42f941bd368018cf397a7f5
linuxlinux>= aa45dadd34e44fcd6a9df4b395bee5b5633b4cec < 76cc4faba0343c6db945b8dc75425b33d633e1b876cc4faba0343c6db945b8dc75425b33d633e1b8
linuxlinux>= aa45dadd34e44fcd6a9df4b395bee5b5633b4cec < c3c06e42e1527716c54f3ad2ced6a034b5f3a489c3c06e42e1527716c54f3ad2ced6a034b5f3a489
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 5.19.1 < 6.6.1286.6.128
linuxlinux_kernel>= 6.13 < 6.18.166.18.16
linuxlinux_kernel>= 6.19 < 6.19.66.19.6
linuxlinux_kernel>= 6.7 < 6.12.756.12.75
ubuntulinux
ubuntulinux-aws
ubuntulinux-aws-6.8
ubuntulinux-aws-fips
ubuntulinux-azure
ubuntulinux-azure-6.8
ubuntulinux-azure-fde
ubuntulinux-azure-fde-6.8
ubuntulinux-azure-fips
ubuntulinux-fips
ubuntulinux-gcp
ubuntulinux-gcp-6.8
ubuntulinux-gcp-fips

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
vendor_ubuntu8.8HIGH
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.