Improper input validation in Linux kernel - CVE-2026-43491
Published: May 20, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper input validation in the qrtr namespace service when handling NEW_SERVER messages. A remote attacker can send a flood of NEW_SERVER messages to cause a denial of service.
Exploitation can exhaust memory by registering excessive servers for a node.
How to mitigate CVE-2026-43491
Sources
- https://git.kernel.org/stable/c/35fb4a0c077c5d1049c2628b769e0a1b1e65df0d
- https://git.kernel.org/stable/c/3efaad55cad1ded429e3a873bfece389058a526b
- https://git.kernel.org/stable/c/868202aa2adae427060a42d5bd663b4d782ec02c
- https://git.kernel.org/stable/c/d5ee2ff98322337951c56398e79d51815acbf955
- https://git.kernel.org/stable/c/e6f6cd501fb54060940a6eb3f4103eeb5e426ae7