Junglewise Threat Intelligence

CVE-2026-43078: Linux Kernel out-of-bounds write in crypto af_alg_pull_tsgl

CVE-2026-43078 · Severity: high · CVSS 7.8 · Published 2026-05-06

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's cryptographic framework that could allow a local user to cause a system crash or potentially gain unauthorized access to data. The issue occurs when the system incorrectly manages memory pages during certain cryptographic operations. This could impact the stability of servers and workstations or lead to a compromise of sensitive information handled by the kernel.

Technical details

An out-of-bounds write vulnerability (CWE-787) exists in the Linux kernel's crypto AF_ALG interface. The root cause is a logic error in the af_alg_pull_tsgl function where a loop responsible for page reassignment was not properly updated, potentially causing it to reassign one more page than allocated in the destination scatterlist. This flaw can be triggered by a local attacker with low privileges to cause memory corruption. Successful exploitation could lead to a denial of service (system crash) or local privilege escalation. The issue has been resolved by adding a check for the 'plen' variable to ensure reassignment only occurs when necessary.

Affected products

  • Linux Linux Kernel 4.14.1 to 5.10.254, 5.11 to 5.15.204, 5.16 to 6.1.170, 6.2 to 6.6.137, 6.7 to 6.12.85, 6.13 to 6.18.24, 6.19 to 6.19.14, 7.0-rc1 to 7.0-rc7

Timeline

  • 2026-04-04: patched: Initial patch authored by Herbert Xu
  • 2026-05-06: disclosed: CVE published
  • 2026-05-06: advisory

References