Out-of-bounds read in Linux kernel - CVE-2026-43006
Published: May 2, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in io_import_fixed() when processing a zero-length fixed buffer import. A local user can submit a specially crafted io_uring request to disclose sensitive information.
The issue is triggered when the buffer address is accepted at the exact end of a registered region with a zero length.