Improper input validation in Linux kernel - CVE-2026-43169
Published: May 7, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper input validation in drm/buddy allocation handling when processing allocation requests with a rounded size that exceeds the available memory manager size. A local user can submit a crafted allocation request to cause a denial of service.
The issue is triggered when size rounding for contiguous, non-contiguous, or large min_block_size allocations produces a value larger than mm->size, leading to a BUG_ON condition.