CVE-2026-43248

HIGH

vhost: move vdpa group bound check to vhost_vdpa

Title source: cna
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: vhost: move vdpa group bound check to vhost_vdpa Remove duplication by consolidating these here. This reduces the posibility of a parent driver missing them. While we're at it, fix a bug in vdpa_sim where a valid ASID can be assigned to a group equal to ngroups, causing an out of bound write.

Scores

CVSS v3 7.8
EPSS 0.0001
EPSS Percentile 2.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-787
Status published
Products (11)
Linux/Linux < 5.19
Linux/Linux 5.19
Linux/Linux 6.12.75 - 6.12.*
Linux/Linux 6.18.16 - 6.18.*
Linux/Linux 6.19.6 - 6.19.*
Linux/Linux 7.0
Linux/Linux bda324fd037a6b0d44da5699574ce741ca161bc4 - 406db68f9cb976a8ddfafd631197264f2307e9c9
Linux/Linux bda324fd037a6b0d44da5699574ce741ca161bc4 - 7441d35d14d9a3d66d925d90cb73c75394e6d454
Linux/Linux bda324fd037a6b0d44da5699574ce741ca161bc4 - cd025c1e876b4e262e71398236a1550486a73ede
Linux/Linux bda324fd037a6b0d44da5699574ce741ca161bc4 - ddb57354634b6ba851b79da45f1de42c646f27d0
... and 1 more
Published May 06, 2026
Tracked Since May 06, 2026