CVE-2026-43211
In the Linux kernel, the following vulnerability has been resolved:
PCI: Fix pci_slot_trylock() error handling
Commit a4e772898f8b ("PCI: Add missing bridge lock to pci_bus_lock()") delegates the bridge device's pci_dev_trylock() to pci_bus_trylock() in pci_slot_trylock(), but it forgets to remove the corresponding pci_dev_unlock() when pci_bus_trylock() fails.
Before a4e772898f8b, the code did:
After a4e772898f8b the bridge-device lock is no longer taken, but the pci_dev_unlock(dev) on the failure path was left in place, leading to the bug.
This yields one of two errors:
Fix it by removing the now-redundant pci_dev_unlock(dev) on the failure path.
Leer descripción completaMostrar menos
[Same patch later posted by Keith at https://patch.msgid.link/20260116184150.3013258-1-kbusch@meta.com]
Detalles técnicos trazas, registros y código del informe original
if (!pci_dev_trylock(dev)) /* <- lock bridge device */
goto unlock;
if (dev->subordinate) {
if (!pci_bus_trylock(dev->subordinate)) {
pci_dev_unlock(dev); /* <- unlock bridge device */
goto unlock;
}
}
1. A warning that the lock is being unlocked when no one holds it.
2. An incorrect unlock of a lock that belongs to another thread.CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 7.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.14%
- Percentil entre todas las CVEs puntuadas: 3
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1068Exploitation for Privilege Escalationprivilege escalation85 % - Impacto principal
T1499.004Application or System Exploitationimpact75 % - Impacto secundario
T1561.002Disk Structure Wipeimpact65 %
Vulnerabilidad local de kernel (AV:L, PR:L) causada por manejo incorrecto de locks que permite a un usuario local causar DoS o corrupción de memoria; acceso local sin interacción (T1068) con impacto de denegación de servicio y manipulación de datos del sistema de archivos.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
CWE
- CWE-667
Referencias
- https://git.kernel.org/stable/c/0425aaf20b407d2f2cf3bf469808e4a35f9abb8b
- https://git.kernel.org/stable/c/8b08ea9690b212b7bf7f12414039259cf34b1aa0
- https://git.kernel.org/stable/c/9368d1ee62829b08aa31836b3ca003803caf0b72
- https://git.kernel.org/stable/c/943ed56606a7ab2fe5a99cad572dd17d484310c7
- https://git.kernel.org/stable/c/a19b61fdb958ffadbba85b43c991eb9fc70c1c1c
- https://git.kernel.org/stable/c/bd435f4b738130d732ef64e0e57e45185f77165d
- https://git.kernel.org/stable/c/ebb27b7399ab8b9eb1f792b329aa5f6250c590d4
- https://git.kernel.org/stable/c/fbe06a3058114bf95a17a4941b205f4b321c6f0a
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-43211",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Secondary",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.8,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "e2355d513b89a2cb511b4ded0deb426cdb01acd0",
"lessThan": "ebb27b7399ab8b9eb1f792b329aa5f6250c590d4",
"versionType": "git"
},
{
"status": "affected",
"version": "04e85a3285b0e5c5af6fd2c0fd6e95ffecc01945",
"lessThan": "fbe06a3058114bf95a17a4941b205f4b321c6f0a",
"versionType": "git"
},
{
"status": "affected",
"version": "7253b4fed46471cc247c6cacefac890a8472c083",
"lessThan": "943ed56606a7ab2fe5a99cad572dd17d484310c7",
"versionType": "git"
},
{
"status": "affected",
"version": "78c6e39fef5c428960aff742149bba302dd46f5a",
"lessThan": "a19b61fdb958ffadbba85b43c991eb9fc70c1c1c",
"versionType": "git"
},
{
"status": "affected",
"version": "a4e772898f8bf2e7e1cf661a12c60a5612c4afab",
"lessThan": "0425aaf20b407d2f2cf3bf469808e4a35f9abb8b",
"versionType": "git"
},
{
"status": "affected",
"version": "a4e772898f8bf2e7e1cf661a12c60a5612c4afab",
"lessThan": "bd435f4b738130d732ef64e0e57e45185f77165d",
"versionType": "git"
},
{
"status": "affected",
"version": "a4e772898f8bf2e7e1cf661a12c60a5612c4afab",
"lessThan": "8b08ea9690b212b7bf7f12414039259cf34b1aa0",
"versionType": "git"
},
{
"status": "affected",
"version": "a4e772898f8bf2e7e1cf661a12c60a5612c4afab",
"lessThan": "9368d1ee62829b08aa31836b3ca003803caf0b72",
"versionType": "git"
},
{
"status": "affected",
"version": "0790b89c7e911003b8c50ae50e3ac7645de1fae9",
"versionType": "git"
},
{
"status": "affected",
"version": "df77a678c33871a6e4ac5b54a71662f1d702335b",
"versionType": "git"
},
{
"status": "affected",
"version": "81c68e218ab883dfa368460a59b674084c0240da",
"versionType": "git"
},
{
"status": "affected",
"version": "5.10.226",
"lessThan": "5.10.252",
"versionType": "semver"
},
{
"status": "affected",
"version": "5.15.167",
"lessThan": "5.15.202",
"versionType": "semver"
},
{
"status": "affected",
"version": "6.1.110",
"lessThan": "6.1.165",
"versionType": "semver"
},
{
"status": "affected",
"version": "6.6.51",
"lessThan": "6.6.128",
"versionType": "semver"
},
{
"status": "affected",
"version": "4.19.322",
"lessThan": "4.20",
"versionType": "semver"
},
{
"status": "affected",
"version": "5.4.284",
"lessThan": "5.5",
"versionType": "semver"
},
{
"status": "affected",
"version": "6.10.10",
"lessThan": "6.11",
"versionType": "semver"
}
],
"programFiles": [
"drivers/pci/pci.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6.11"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "6.11",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "5.10.252",
"versionType": "semver",
"lessThanOrEqual": "5.10.*"
},
{
"status": "unaffected",
"version": "5.15.202",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.1.165",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.128",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.75",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.16",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "6.19.6",
"versionType": "semver",
"lessThanOrEqual": "6.19.*"
},
{
"status": "unaffected",
"version": "7.0",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/pci/pci.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-05-06T12:16:40.527",
"references": [
{
"url": "https://git.kernel.org/stable/c/0425aaf20b407d2f2cf3bf469808e4a35f9abb8b",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/8b08ea9690b212b7bf7f12414039259cf34b1aa0",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/9368d1ee62829b08aa31836b3ca003803caf0b72",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/943ed56606a7ab2fe5a99cad572dd17d484310c7",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/a19b61fdb958ffadbba85b43c991eb9fc70c1c1c",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/bd435f4b738130d732ef64e0e57e45185f77165d",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/ebb27b7399ab8b9eb1f792b329aa5f6250c590d4",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/fbe06a3058114bf95a17a4941b205f4b321c6f0a",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-667"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nPCI: Fix pci_slot_trylock() error handling\n\nCommit a4e772898f8b (\"PCI: Add missing bridge lock to pci_bus_lock()\")\ndelegates the bridge device's pci_dev_trylock() to pci_bus_trylock() in\npci_slot_trylock(), but it forgets to remove the corresponding\npci_dev_unlock() when pci_bus_trylock() fails.\n\nBefore a4e772898f8b, the code did:\n\n if (!pci_dev_trylock(dev)) /* <- lock bridge device */\n goto unlock;\n if (dev->subordinate) {\n if (!pci_bus_trylock(dev->subordinate)) {\n pci_dev_unlock(dev); /* <- unlock bridge device */\n goto unlock;\n }\n }\n\nAfter a4e772898f8b the bridge-device lock is no longer taken, but the\npci_dev_unlock(dev) on the failure path was left in place, leading to the\nbug.\n\nThis yields one of two errors:\n\n 1. A warning that the lock is being unlocked when no one holds it.\n 2. An incorrect unlock of a lock that belongs to another thread.\n\nFix it by removing the now-redundant pci_dev_unlock(dev) on the failure\npath.\n\n[Same patch later posted by Keith at\nhttps://patch.msgid.link/20260116184150.3013258-1-kbusch@meta.com]"
}
],
"lastModified": "2026-06-17T10:49:09.683",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A3FCD7A0-ABE5-49E8-A47C-F0169215C4B7",
"versionEndExcluding": "4.20",
"versionStartIncluding": "4.19.322"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "69E2B19B-E681-4963-ABD2-D4141E9A6B64",
"versionEndExcluding": "5.5",
"versionStartIncluding": "5.4.284"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "46ED7BB3-F580-4BF5-AF52-3D115F1A672E",
"versionEndExcluding": "5.10.252",
"versionStartIncluding": "5.10.226"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CA8574EF-E0E5-423A-A5D7-CEDCF7FDEB8C",
"versionEndExcluding": "5.15.202",
"versionStartIncluding": "5.15.167"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D575C1E8-668C-41F9-8A8F-30FDF5C45F1A",
"versionEndExcluding": "6.1.165",
"versionStartIncluding": "6.1.110"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E939C709-7387-4CDF-B846-AD633A16F152",
"versionEndExcluding": "6.6.128",
"versionStartIncluding": "6.6.51"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FF19907D-B1E9-49EB-8A88-5F3EF276ADDE",
"versionEndExcluding": "6.12.75",
"versionStartIncluding": "6.10.10"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B4B8CDA9-BADF-4CF5-8B3B-702DE8EEA40B",
"versionEndExcluding": "6.18.16",
"versionStartIncluding": "6.13"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "373EEEDA-FAA1-4FB4-B6ED-DB4DD99DBE67",
"versionEndExcluding": "6.19.6",
"versionStartIncluding": "6.19"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}