Improper input validation in Linux kernel - CVE-2026-43081
Published: May 7, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper input validation in GENERIC_CMD register field masks in the net/ipa component when handling stop commands for the MPSS remote processor while IPA is active. A local user can trigger the affected operation to cause a denial of service.
The issue was observed as a kernel WARN when sending a stop command to the MPSS remote processor while IPA was up.
How to mitigate CVE-2026-43081
Sources
- https://git.kernel.org/stable/c/2aa50d2c1f631b405849da246043c6f683af7489
- https://git.kernel.org/stable/c/9709b56d908acc120fe8b4ae250b3c9d749ea832
- https://git.kernel.org/stable/c/a7d326dfb13b5a0763eccfd78836fe15199fc499
- https://git.kernel.org/stable/c/bafc45ea30d297002750396d5f10e3018bf2cd60
- https://git.kernel.org/stable/c/d1c66396796f23f7201b1addf06f62515035354d