CVE-2026-43475
Description
A flaw was found in the Linux kernel's hv_storvsc component. When the kernel is configured with PREEMPT_RT (Real-Time Preemption) and running on a Hyper-V virtual machine, a local process performing specific I/O operations can trigger a concurrency issue. This can lead to a system lock-up or crash, resulting in a denial of service.
Statement
A Moderate impact denial of service flaw was identified in the Linux kernel's hv_storvsc component. This issue affects Red Hat Enterprise Linux systems when running a kernel configured with Real-Time Preemption (PREEMPT_RT) as a guest on a Hyper-V virtual machine. A local attacker could exploit a concurrency issue by performing specific I/O operations, leading to a system lock-up or crash.
Mitigation
To mitigate this issue, prevent the `hv_storvsc` kernel module from loading. This can be achieved by creating a blacklist rule. Note that this may impact functionality if Hyper-V storage is required. A system reboot is required for the change to take effect.
Create a file named `/etc/modprobe.d/blacklist-hv_storvsc.conf` with the following content:
`blacklist hv_storvsc`
Then, regenerate the initramfs:
`dracut -f -v`
Finally, reboot the system:
`reboot`
Common Vulnerability Scoring System (CVSS) Score Details
Info alert:Important note
CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).
The following CVSS metrics and score provided are preliminary and subject to review.
CVSS v3 Score Breakdown
| Red Hat | NVD | cve.org | |
|---|---|---|---|
| Base Score | 5.5 | 5.5 | N/A |
| Attack Vector | Local | Local | N/A |
| Attack Complexity | Low | Low | N/A |
| Privileges Required | Low | Low | N/A |
| User Interaction | None | None | N/A |
| Scope | Unchanged | Unchanged | N/A |
| Confidentiality | None | None | N/A |
| Integrity Impact | None | None | N/A |
| Availability Impact | High | High | N/A |
Vector
Red Hat: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
NVD: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Understanding the Weakness (CWE)
Integrity,Confidentiality,Other
Technical Impact: Modify Application Data; Read Application Data; Alter Execution Logic
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.