CVE-2026-43484

MEDIUM EPSS 1.8%
Published May 13, 20261mo ago · Modified Jun 26, 20261w ago
5.5 CVSS 3.1
Medium
Find Similar
Published May 13, 2026 1mo ago
Last Modified Jun 26, 2026 1w ago

Description

In the Linux kernel, the following vulnerability has been resolved: mmc: core: Avoid bitfield RMW for claim/retune flags Move claimed and retune control flags out of the bitfield word to avoid unrelated RMW side effects in asynchronous contexts. The host->claimed bit shared a word with retune flags. Writes to claimed in __mmc_claim_host() or retune_now in mmc_mq_queue_rq() can overwrite other bits when concurrent updates happen in other contexts, triggering spurious WARN_ON(!host->claimed). Convert claimed, can_retune, retune_now and retune_paused to bool to remove shared-word coupling.

CVSS Details

Base Score
5.5
Exploitability
1.8
Impact
3.6
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Vector Local
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality None
Integrity None
Availability High

Threat Intelligence

EPSS Exploit Probability
1.8% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Affected Products 7

VendorProductVersionRange
linuxlinux_kernel*≥4.15  –  <5.15.203
linuxlinux_kernel*≥5.16  –  <6.1.167
linuxlinux_kernel*≥6.2  –  <6.6.130
linuxlinux_kernel*≥6.7  –  <6.12.78
linuxlinux_kernel*≥6.13  –  <6.18.19
linuxlinux_kernel*≥6.19  –  <6.19.9
linuxlinux_kernel7.0any

References 7

  • git.kernel.org https://git.kernel.org/stable/c/0e06cc511c61cff1591e5435a207759adcc76b6d
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/270277c2ab631044867adb1bd2f2433d3892de6e
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/41dce4dae583a8ce06a7ebf4ce704c46a142957c
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/45038e03f15e992c48603fff8c6b1c9be5397ac9
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/901084c51a0a8fb42a3f37d2e9c62083c495f824
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/bb7fc2498c3bb25fa6a91f22f4760005325cfbd5
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/d3a3caf44c8ec26f5d63dc17c1c7242effa60ebc
    Patch

Remediation

  • git.kernel.org https://git.kernel.org/stable/c/0e06cc511c61cff1591e5435a207759adcc76b6d
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/270277c2ab631044867adb1bd2f2433d3892de6e
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/41dce4dae583a8ce06a7ebf4ce704c46a142957c
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/45038e03f15e992c48603fff8c6b1c9be5397ac9
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/901084c51a0a8fb42a3f37d2e9c62083c495f824
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/bb7fc2498c3bb25fa6a91f22f4760005325cfbd5
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/d3a3caf44c8ec26f5d63dc17c1c7242effa60ebc
    Patch