Out-of-bounds read in Linux kernel - CVE-2026-43197

 

Out-of-bounds read in Linux kernel - CVE-2026-43197

Published: May 7, 2026


Vulnerability identifier: #VU130541
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-43197
CWE-ID: CWE-125
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to an out-of-bounds read in netconsole_write when processing console messages that are not nul-terminated. A local user can trigger processing of a specially crafted message to cause a denial of service.


Affected software

Linux kernel
Debian Linux
Ubuntu
Anolis OS
openEuler
kernel-tools
kernel
bpftool
bpftool-debuginfo
kernel-debuginfo
kernel-debugsource
kernel-devel
kernel-headers
kernel-source
kernel-tools-debuginfo
kernel-tools-devel
perf
perf-debuginfo
python3-perf
python3-perf-debuginfo
kernel-extra-modules
kernel-debug-devel
kernel-debug
kernel-tools-libs
kernel-tools-libs-devel
linux (Ubuntu package)
linux-lowlatency (Ubuntu package)
linux-hwe-6.8 (Ubuntu package)
linux-oracle-6.8 (Ubuntu package)
linux-aws-6.8 (Ubuntu package)
linux-raspi (Ubuntu package)
linux (Debian package)
linux-hwe-6.17 (Ubuntu package)
linux-azure-fde-6.17 (Ubuntu package)
linux-azure-6.17 (Ubuntu package)
linux-nvidia-6.17 (Ubuntu package)
linux-oem-6.17 (Ubuntu package)

How to mitigate CVE-2026-43197

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3
kernel-tools - addressed in versions 6.6.0-145.1.19.156, 6.6.0-145.3.16.148
kernel - addressed in versions 6.6.0-145.1.19.156, 6.6.0-145.3.16.148
bpftool - addressed in versions 6.6.0-145.1.19.156, 6.6.0-145.3.16.148
bpftool-debuginfo - addressed in versions 6.6.0-145.1.19.156, 6.6.0-145.3.16.148
kernel-debuginfo - addressed in versions 6.6.0-145.1.19.156, 6.6.0-145.3.16.148
kernel-debugsource - addressed in versions 6.6.0-145.1.19.156, 6.6.0-145.3.16.148
kernel-devel - addressed in versions 6.6.0-145.1.19.156, 6.6.0-145.3.16.148
kernel-headers - addressed in versions 6.6.0-145.1.19.156, 6.6.0-145.3.16.148
kernel-source - addressed in versions 6.6.0-145.1.19.156, 6.6.0-145.3.16.148
kernel-tools-debuginfo - addressed in versions 6.6.0-145.1.19.156, 6.6.0-145.3.16.148
kernel-tools-devel - addressed in versions 6.6.0-145.1.19.156, 6.6.0-145.3.16.148
perf - addressed in versions 6.6.0-145.1.19.156, 6.6.0-145.3.16.148
perf-debuginfo - addressed in versions 6.6.0-145.1.19.156, 6.6.0-145.3.16.148
python3-perf - addressed in versions 6.6.0-145.1.19.156, 6.6.0-145.3.16.148
python3-perf-debuginfo - addressed in versions 6.6.0-145.1.19.156, 6.6.0-145.3.16.148
kernel-extra-modules - update to 6.6.0-145.3.16.148
perf - update to 6.6.102-7
kernel-debug-devel - update to 6.6.102-7
kernel-debug - update to 6.6.102-7
kernel - update to 6.6.102-7
bpftool - update to 6.6.102-7
kernel-devel - update to 6.6.102-7
kernel-headers - update to 6.6.102-7
kernel-tools - update to 6.6.102-7
kernel-tools-libs - update to 6.6.102-7
kernel-tools-libs-devel - update to 6.6.102-7
python3-perf - update to 6.6.102-7
linux (Ubuntu package) - addressed in versions 6.8.0-137.137+fips1, 6.8.0-1034.35, 6.8.0-1047.51, 6.8.0-1060.63.1, 6.8.0-1060.63~22.04.1, 6.8.0-1060.68, 6.8.0-1062.63, 6.8.0-1062.63~22.04.1, 6.8.0-1062.65, 6.8.0-1062.65+fips1, 6.8.0-1063.70, 6.8.0-1063.70~22.04.1, 6.8.0-1064.72+fips1, 6.8.0-1064.72~22.04.1, 6.8.0-1065.73, 6.8.0-1065.73+fips1, 6.8.0-1065.73~22.04.1, 6.8.1-1057.58, 6.8.1-1057.58~22.04.1, 6.17.0-40.40
linux-lowlatency (Ubuntu package) - addressed in versions 6.8.0-137.137.1, 6.8.0-137.137.1~22.04.1, 6.8.0-1031.32, 6.8.0-1059.62
linux-hwe-6.8 (Ubuntu package) - update to 6.8.0-138.138~22.04.1
linux-oracle-6.8 (Ubuntu package) - update to 6.8.0-1059.62~22.04.1
linux-aws-6.8 (Ubuntu package) - update to 6.8.0-1062.65~22.04.1
linux-raspi (Ubuntu package) - addressed in versions 6.8.0-1062.66, 6.8.0-2051.53, 6.17.0-1021.21
linux (Debian package) - update to 6.12.105-1
linux-hwe-6.17 (Ubuntu package) - update to 6.17.0-40.40~24.04.1
linux-azure-fde-6.17 (Ubuntu package) - update to 6.17.0-1018.18~24.04.1
linux-azure-6.17 (Ubuntu package) - update to 6.17.0-1021.21~24.04.1
linux-nvidia-6.17 (Ubuntu package) - update to 6.17.0-1026.26
linux-oem-6.17 (Ubuntu package) - update to 6.17.0-1028.28

External References

Related Security Bulletins