Junglewise Threat Intelligence

CVE-2026-43108: Linux Kernel Qualcomm pd-mapper decoding error in soc driver

CVE-2026-43108 · Severity: medium · CVSS 5.5 · Published 2026-05-06

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's Qualcomm SoC driver could lead to system instability or a denial of service. The issue occurs when the system attempts to process error messages following a peripheral crash, where a mismatch in data lengths causes a decoding failure. This primarily affects the reliability of service management on devices using Qualcomm processors.

Technical details

A vulnerability exists in the Qualcomm pd-mapper (Protection Domain Mapper) implementation in the Linux kernel due to an incorrect element length declaration in the 'servreg_loc_pfr_req_ei' structure. The 'reason' field length in the QMI (Qualcomm Messaging Interface) element info did not match the actual 'servreg_loc_pfr_req' structure definition. This discrepancy causes 'qmi_decode_string_elem' to fail with a decoding error (e.g., String len 81 >= Max Len 65) when a Protection Domain (PD) crashes and attempts to report the crash reason. An attacker with local access could potentially exploit this to cause a kernel-level denial of service or prevent proper recovery of crashed services. The issue has been resolved by synchronizing the element length with the 'SERVREG_PFR_LENGTH' constant.

Affected products

  • Linux Linux Kernel 6.11 to 6.12.83, 6.13 to 6.18.24, 6.19 to 6.19.14, 7.0-rc1 to 7.0-rc7

Timeline

  • 2026-01-29: other: Patch authored
  • 2026-05-06: disclosed: CVE published
  • 2026-05-11: advisory: NVD enrichment and analysis completed

References

Related threats