A flaw tracked as CVE-2026-43158 in the Linux kernel's XFS filesystem can let a local user trigger a denial of service by causing an assertion failure and filesystem shutdown. The bug affects XFS attribute leaf block handling during repeated setxattr operations: crafted extended attribute insertions can corrupt freemap accounting so that the entries array overlaps free space. The issue is classified as CWE-617 Reachable Assertion, carries a CVSS v3 score of 7.0 from Red Hat, and traces back to code introduced in Linux 2.6.12.
The Linux kernel community published fixes across multiple stable branches, with maintainers advising organizations to update to current stable kernels rather than cherry-pick patches. Red Hat said no acceptable mitigation is available and shipped fixes through updated RHEL kernel packages and errata, including advisory RHSA-2026:27735 for RHEL 9.4 Update Services for SAP Solutions and related variants. That advisory bundles CVE-2026-43158 with other kernel vulnerabilities in components including libceph, netfilter, SMB/CIFS, SCTP, and mac80211, and requires affected systems to be rebooted after installation.

See affected versions and whether adversaries are exploiting it.
10 events from the most recent confirmed update back to the earliest known activity.
Red Hat released fixes for CVE-2026-43158 in RHEL 10 kernel packages via RHSA-2026:21557 and in RHEL 8 kernel and kernel-rt packages via RHSA-2026:21706 and RHSA-2026:21745.
Red Hat published its CVE record for CVE-2026-43158, describing the XFS flaw as a moderate-severity reachable assertion issue with no acceptable mitigation currently available.
Upstream fixes for CVE-2026-43158 were released in Linux 5.10.252, 5.15.202, 6.1.165, 6.6.128, 6.12.75, 6.18.16, 6.19.6, and 7.0, correcting XFS freemap adjustments when adding xattrs to leaf blocks.
The Linux kernel CVE team assigned CVE-2026-43158 to an XFS vulnerability that can trigger an assertion failure and filesystem shutdown when crafted xattr operations cause freemap overlap with the entries array.
The XFS extended-attribute freemap accounting flaw behind CVE-2026-43158 was introduced in Linux 2.6.12 by commit 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2.
Red Hat issued RHSA-2026:41236 to fix CVE-2026-43158 in Red Hat Enterprise Linux 7 Extended Lifecycle Support kernel-rt packages.
Red Hat last modified its CVE-2026-43158 record, reflecting an update to the vendor's vulnerability entry.
Red Hat fixed CVE-2026-43158 in Red Hat Enterprise Linux 10.0 Extended Update Support kernel packages via advisory RHSA-2026:33215.
Red Hat released RHEL 7 Extended Lifecycle Support kernel packages fixing CVE-2026-43158 in RHSA-2026:27729, and published RHSA-2026:27735 for RHEL 9.4 Update Services for SAP Solutions and related variants, also addressing the flaw.
Red Hat issued additional fixes for CVE-2026-43158 in RHEL 8.4 and 8.6 Advanced Mission Critical Update Support and Extended Update Support Long-Life Add-On kernel packages through RHSA-2026:26535 and RHSA-2026:26570.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceredhat.com
Open sourcelore.kernel.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.