Junglewise Threat Intelligence

CVE-2026-43141: Linux Kernel shift-out-of-bounds in ntb_hw_switchtec

CVE-2026-43141 · Severity: high · CVSS 7.1 · Published 2026-05-06

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's Switchtec Non-Transparent Bridge (NTB) driver. This component is used for high-speed data transfer between different computer systems. An attacker with local access could exploit this flaw to cause a system crash or potentially access sensitive information from the system's memory.

Technical details

A shift-out-of-bounds vulnerability exists in the ntb_hw_switchtec driver within the Linux kernel. The root cause is an unchecked call to rounddown_pow_of_two() when the number of Memory Window (MW) Look Up Tables (LUT) is configured to zero. In such scenarios, the mathematical operation results in undefined behavior. A local attacker with low privileges can trigger this condition to cause a denial of service (system crash) or an out-of-bounds read (CWE-125). The issue has been patched across multiple stable kernel branches by adding a conditional check to ensure the value is non-zero before performing the power-of-two calculation.

Affected products

  • Linux Linux Kernel 4.15 to 5.10.251, 5.11 to 5.15.201, 5.16 to 6.1.164, 6.2 to 6.6.127, 6.7 to 6.12.74, 6.13 to 6.18.15, 6.19 to 6.19.5

Timeline

  • 2026-05-06: disclosed
  • 2026-05-06: advisory
  • 2026-02-20: patched: Initial patch committed to stable tree

References

Related threats