Junglewise Threat Intelligence

CVE-2026-43006: Linux Kernel out-of-bounds read in io_uring fixed buffer import

CVE-2026-43006 · Severity: high · CVSS 7.1 · Published 2026-05-01

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was found in the Linux kernel's io_uring subsystem, which is used for high-performance input/output operations. An error in how the system handles zero-length data buffers allows a local attacker to trigger an out-of-bounds memory read. This could lead to the exposure of sensitive kernel information or cause a system crash, potentially disrupting operations.

Technical details

An out-of-bounds read vulnerability exists in the Linux kernel's io_uring/rsrc component. The function validate_fixed_range() incorrectly allows a buffer address at the exact end of a registered region when the length is zero due to a strict greater-than check. This causes io_import_fixed() to compute an offset equal to the buffer length, leading the bvec skip logic to read from out-of-bounds slab memory. A local attacker can exploit this to read kernel memory or cause a denial of service (kernel panic). The issue has been resolved by adding an early return in io_import_fixed() for zero-length imports.

Affected products

  • Linux Linux Kernel 6.15 to 6.18.22, 6.19 to 6.19.12, 7.0-rc1 to 7.0-rc6

Timeline

  • 2026-03-30: other: Patch authored
  • 2026-05-01: disclosed
  • 2026-05-01: advisory

References

Related threats