Improper Check or Handling of Exceptional Conditions in Linux kernel - CVE-2026-43344

 

Improper Check or Handling of Exceptional Conditions in Linux kernel - CVE-2026-43344

Published: May 9, 2026


Vulnerability identifier: #VU130837
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2026-43344
CWE-ID: CWE-703
Exploitation vector: Local access
Exploit availability: No public exploit available
Vendor: Linux Foundation
Affected software:
Linux kernel

Detailed vulnerability description

The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper handling of offline CPU and topology lookup conditions in the Intel uncore PMON initialization logic when initializing uncore PCI devices on affected platforms. A local user can trigger the vulnerable code path to cause a denial of service.

The issue can occur when all CPUs associated with a UBOX device are offline or when NUMA is disabled on a NUMA-capable platform.


How to mitigate CVE-2026-43344

Install security update from vendor's repository.

Sources