Out-of-bounds read in Linux kernel - CVE-2026-43241
Published: May 7, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in the ntb_hw_switchtec driver when handling NTB configurations with an invalid memory window index. A local user can trigger access to an invalid mw_sizes array index to cause a denial of service.
The issue occurs because the number of memory window lookup table entries depends on the NTB configuration and may be set to MAX_MWS.
How to mitigate CVE-2026-43241
Sources
- https://git.kernel.org/stable/c/0e930420945106151c6eb3d7837b4e6154e9b144
- https://git.kernel.org/stable/c/2346856b74823a2a78109002e479a3d02526a9ce
- https://git.kernel.org/stable/c/348e1ac9ad983ed7e62de14e1daf47f1695a4ce9
- https://git.kernel.org/stable/c/47ce292dd45dc689747c40603222691638919189
- https://git.kernel.org/stable/c/740945de896021b9a859e71f38f6aea72a6393cf
- https://git.kernel.org/stable/c/85c9daa1f8319bbb3dfee71dc6a2f969cd3b4c92
- https://git.kernel.org/stable/c/c8ba7ad2cc1c7b90570aa347b8ebbe279f1eface
- https://git.kernel.org/stable/c/ee02c4f980c91820845dd8e469ec7dc670ab6d9d