CVE-2026-43211 Details
Description
In the Linux kernel, the following vulnerability has been resolved: PCI: Fix pci_slot_trylock() error handling Commit a4e772898f8b ("PCI: Add missing bridge lock to pci_bus_lock()") delegates the bridge device's pci_dev_trylock() to pci_bus_trylock() in pci_slot_trylock(), but it forgets to remove the corresponding pci_dev_unlock() when pci_bus_trylock() fails. Before a4e772898f8b, the code did: if (!pci_dev_trylock(dev)) /* <- lock bridge device */ goto unlock; if (dev->subordinate) { if (!pci_bus_trylock(dev->subordinate)) { pci_dev_unlock(dev); /* <- unlock bridge device */ goto unlock; } } After a4e772898f8b the bridge-device lock is no longer taken, but the pci_dev_unlock(dev) on the failure path was left in place, leading to the bug. This yields one of two errors: 1. A warning that the lock is being unlocked when no one holds it. 2. An incorrect unlock of a lock that belongs to another thread. Fix it by removing the now-redundant pci_dev_unlock(dev) on the failure path. [Same patch later posted by Keith at https://patch.msgid.link/[email protected]]
A vulnerability in the Linux kernel's PCI handling has been addressed. The issue arose in the 'pci_slot_trylock()' function, where the management of locks for bridge devices was improperly handled. Specifically, a recent commit introduced a change that delegated the locking of bridge devices to a bus-level lock, but failed to correctly manage the unlocking process when the operation did not succeed. This oversight could lead to warnings about unlocking a lock that was never acquired, or incorrectly releasing a lock that belongs to a different thread.
Users can apply the latest patches available in the Linux kernel stable tree to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/0425aaf20b407d2f2cf3bf469808e4a35f9abb8b | kernel.org | Patch |
| https://git.kernel.org/stable/c/8b08ea9690b212b7bf7f12414039259cf34b1aa0 | kernel.org | Patch |
| https://git.kernel.org/stable/c/9368d1ee62829b08aa31836b3ca003803caf0b72 | kernel.org | Patch |
| https://git.kernel.org/stable/c/943ed56606a7ab2fe5a99cad572dd17d484310c7 | kernel.org | Patch |
| https://git.kernel.org/stable/c/a19b61fdb958ffadbba85b43c991eb9fc70c1c1c | kernel.org | Patch |
| https://git.kernel.org/stable/c/bd435f4b738130d732ef64e0e57e45185f77165d | kernel.org | Patch |
| https://git.kernel.org/stable/c/ebb27b7399ab8b9eb1f792b329aa5f6250c590d4 | kernel.org | Patch |
| https://git.kernel.org/stable/c/fbe06a3058114bf95a17a4941b205f4b321c6f0a | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-667 | Improper Locking | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 4.19.322, < 4.20 >= 5.4.284, < 5.5 >= 5.10.226, < 5.10.252 >= 5.15.167, < 5.15.202 >= 6.1.110, < 6.1.165 >= 6.6.51, < 6.6.128 >= 6.10.10, < 6.12.75 >= 6.13, < 6.18.16 >= 6.19, < 6.19.6 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | kernel.org |
| May 11, 2026 | Initial Analysis | [email protected] |
| May 8, 2026 | CVE Modified | kernel.org |
| May 6, 2026 | New CVE Received | kernel.org |