CVE-2026-43215
Description
In the Linux kernel, the following vulnerability has been resolved: cifs: Fix locking usage for tcon fields We used to use the cifs_tcp_ses_lock to protect a lot of objects that are not just the server, ses or tcon lists. We later introduced srv_lock, ses_lock and tc_lock to protect fields within the corresponding structs. This was done to provide a more granular protection and avoid unnecessary serialization. There were still a couple of uses of cifs_tcp_ses_lock to provide tcon fields. In this patch, I've replaced them with tc_lock.
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2026-43215
Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2026-43215.html
Vendor advisory: 416baaa9-dc9f-4396-8d5f-8c081fb06d67 — https://git.kernel.org/stable/c/96c4af418586ee9a6aab61738644366426e05316
Vendor advisory: 416baaa9-dc9f-4396-8d5f-8c081fb06d67 — https://git.kernel.org/stable/c/953953abb66e52c224057ab91e404284fefeab62
Vendor advisory: 416baaa9-dc9f-4396-8d5f-8c081fb06d67 — https://git.kernel.org/stable/c/8c59eeeeffa1524ef57e173a89a1a3ff539888d5
Vendor advisory: 416baaa9-dc9f-4396-8d5f-8c081fb06d67 — https://git.kernel.org/stable/c/601dd3b79769b38d30b693c40afdb2a4b7edf9d0
Vendor advisory: 416baaa9-dc9f-4396-8d5f-8c081fb06d67 — https://git.kernel.org/stable/c/3969db6b22e3d90d8c5f22ac1a7fe0350a94c136
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| sles | affected | | |
| debian | bookworm | affected | |
| debian | bullseye | fixed | 0 |
| debian | forky | fixed | 6.19.6-1 |
| debian | sid | fixed | 6.19.6-1 |
| debian | trixie | fixed | 6.12.85-1 |
| linux-kernel | affected | 6.6.128 |
References
- https://git.kernel.org/stable/c/3969db6b22e3d90d8c5f22ac1a7fe0350a94c136
- https://git.kernel.org/stable/c/601dd3b79769b38d30b693c40afdb2a4b7edf9d0
- https://git.kernel.org/stable/c/8c59eeeeffa1524ef57e173a89a1a3ff539888d5
- https://git.kernel.org/stable/c/953953abb66e52c224057ab91e404284fefeab62
- https://git.kernel.org/stable/c/96c4af418586ee9a6aab61738644366426e05316
- https://www.suse.com/security/cve/CVE-2026-43215.html
- https://security-tracker.debian.org/tracker/CVE-2026-43215
CWEs
CWE-667
Verify integrity in audit chain (admin only). AS-IS.