HOMEVULNERABILITIESCVE-2026-43471
NONE

CVE-2026-43471

Published: May 8, 2026· Updated: May 12, 2026

EPSS:0.02%probability of exploitation in 30 daysPercentile:4.9th

Official Description

In the Linux kernel, the following vulnerability has been resolved:

scsi: ufs: core: Fix possible NULL pointer dereference in ufshcd_add_command_trace()

The kernel log indicates a crash in ufshcd_add_command_trace, due to a NULL

pointer dereference when accessing hwq->id. This can happen if

ufshcd_mcq_req_to_hwq() returns NULL.

This patch adds a NULL check for hwq before accessing its id field to

prevent a kernel crash.

Kernel log excerpt:

[<ffffffd5d192dc4c>] notify_die+0x4c/0x8c

[<ffffffd5d1814e58>] __die+0x60/0xb0

[<ffffffd5d1814d64>] die+0x4c/0xe0

[<ffffffd5d181575c>] die_kernel_fault+0x74/0x88

[<ffffffd5d1864db4>] __do_kernel_fault+0x314/0x318

[<ffffffd5d2a3cdf8>] do_page_fault+0xa4/0x5f8

[<ffffffd5d2a3cd34>] do_translation_fault+0x34/0x54

[<ffffffd5d1864524>] do_mem_abort+0x50/0xa8

[<ffffffd5d2a297dc>] el1_abort+0x3c/0x64

[<ffffffd5d2a29718>] el1h_64_sync_handler+0x44/0xcc

[<ffffffd5d181133c>] el1h_64_sync+0x80/0x88

[<ffffffd5d255c1dc>] ufshcd_add_command_trace+0x23c/0x320

[<ffffffd5d255bad8>] ufshcd_compl_one_cqe+0xa4/0x404

[<ffffffd5d2572968>] ufshcd_mcq_poll_cqe_lock+0xac/0x104

[<ffffffd5d11c7460>] ufs_mtk_mcq_intr+0x54/0x74 [ufs_mediatek_mod]

[<ffffffd5d19ab92c>] __handle_irq_event_percpu+0xc8/0x348

[<ffffffd5d19abca8>] handle_irq_event+0x3c/0xa8

[<ffffffd5d19b1f0c>] handle_fasteoi_irq+0xf8/0x294

[<ffffffd5d19aa778>] generic_handle_domain_irq+0x54/0x80

[<ffffffd5d18102bc>] gic_handle_irq+0x1d4/0x330

[<ffffffd5d1838210>] call_on_irq_stack+0x44/0x68

[<ffffffd5d183af30>] do_interrupt_handler+0x78/0xd8

[<ffffffd5d2a29c00>] el1_interrupt+0x48/0xa8

[<ffffffd5d2a29ba8>] el1h_64_irq_handler+0x14/0x24

[<ffffffd5d18113c4>] el1h_64_irq+0x80/0x88

[<ffffffd5d2527fb4>] arch_local_irq_enable+0x4/0x1c

[<ffffffd5d25282e4>] cpuidle_enter+0x34/0x54

[<ffffffd5d195a678>] do_idle+0x1dc/0x2f8

[<ffffffd5d195a7c4>] cpu_startup_entry+0x30/0x3c

[<ffffffd5d18155c4>] secondary_start_kernel+0x134/0x1ac

[<ffffffd5d18640bc>] __secondary_switched+0xc4/0xcc

NVD Source

Technical Analysis

CVE-2026-43471 requires local access, meaning attackers must already have a foothold on the target system.

Exploitation requires some privileges, which limits the exposure to scenarios where an attacker has already gained initial access.

Affected Vendors & Products

Mentioned vendors (from description):
Linux
CPE data not yet available in NVD for this CVE.

Exploit & PoC Resources

NO KNOWN EXPLOITNo public exploit confirmed at this time
External links open in a new tab. Always verify in a controlled environment before use.

All References (5)

Quick Facts

CVE IDCVE-2026-43471
SeverityNONE
CISA KEVNo
EPSS (30d)0.02%
PublishedMay 8, 2026

Recommended Actions

  • Apply vendor patches immediately
  • Monitor CVE-2026-43471 in threat intel feeds
  • Review IDS/IPS signatures for exploitation attempts
Data sourced from NVD (NIST), CISA KEV, and EPSS (FIRST). Analysis generated by CTIWATCH.COM. CVE data is provided under the NVD usage policy.