CVE-2026-43475

Description

A flaw was found in the Linux kernel's hv_storvsc component. When the kernel is configured with PREEMPT_RT (Real-Time Preemption) and running on a Hyper-V virtual machine, a local process performing specific I/O operations can trigger a concurrency issue. This can lead to a system lock-up or crash, resulting in a denial of service.

Statement

A Moderate impact denial of service flaw was identified in the Linux kernel's hv_storvsc component. This issue affects Red Hat Enterprise Linux systems when running a kernel configured with Real-Time Preemption (PREEMPT_RT) as a guest on a Hyper-V virtual machine. A local attacker could exploit a concurrency issue by performing specific I/O operations, leading to a system lock-up or crash.

Mitigation

To mitigate this issue, prevent the `hv_storvsc` kernel module from loading. This can be achieved by creating a blacklist rule. Note that this may impact functionality if Hyper-V storage is required. A system reboot is required for the change to take effect.

Create a file named `/etc/modprobe.d/blacklist-hv_storvsc.conf` with the following content:
`blacklist hv_storvsc`

Then, regenerate the initramfs:
`dracut -f -v`

Finally, reboot the system:
`reboot`

Common Vulnerability Scoring System (CVSS) Score Details

Info alert:Important note

CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).

The following CVSS metrics and score provided are preliminary and subject to review.

CVSS v3 Score Breakdown

Red HatNVDcve.org
Base Score5.55.5N/A
Attack VectorLocalLocalN/A
Attack ComplexityLowLowN/A
Privileges RequiredLowLowN/A
User InteractionNoneNoneN/A
ScopeUnchangedUnchangedN/A
ConfidentialityNoneNoneN/A
Integrity ImpactNoneNoneN/A
Availability ImpactHighHighN/A

Vector

Red Hat: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

NVD: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Understanding the Weakness (CWE)

Integrity,Confidentiality,Other

Technical Impact: Modify Application Data; Read Application Data; Alter Execution Logic

Frequently Asked Questions

Want to get errata notifications? Sign up here.