Out-of-bounds read in Linux kernel - CVE-2026-43280
Published: May 7, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in xe_pat_index_get_coh_mode() when handling the madvise ioctl with a crafted pat_index value. A local user can supply a bogus pat_index value to disclose sensitive information.
The unsafe access occurs from the xe->pat.table array, and the issue can still be reached in production kernels.