Junglewise Threat Intelligence

CVE-2026-43150: Linux Kernel out-of-bounds write in perf/arm-cmn

CVE-2026-43150 · Severity: high · CVSS 7.8 · Published 2026-05-06

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability exists in the Linux kernel's performance monitoring subsystem for ARM Coherent Mesh Network (CMN) hardware. The driver previously accepted unknown or newer hardware configurations that exceeded its internal limits, which could lead to memory corruption. An attacker with local access could potentially exploit this to crash the system or gain unauthorized privileges.

Technical details

A vulnerability in the perf/arm-cmn driver in the Linux kernel stems from the driver being overly permissive when encountering unknown ARM Coherent Mesh Network (CMN) models or revisions. The driver makes static assumptions about maximum supported sizes and node counts; when hardware exceeds these internal limits (e.g., Logical IDs or Mesh dimensions), it can result in an out-of-bounds write (CWE-787) and subsequent memory corruption. This is a local attack vector requiring low privileges. The fix introduces strict validation during hardware discovery to reject configurations that exceed CMN_MAX_NODES_PER_EVENT or CMN_MAX_DIMENSION. Patches have been released across multiple stable kernel branches.

Affected products

  • Linux Linux Kernel 6.1.63 to 6.1.165, 6.5 to 6.6.128, 6.7 to 6.12.75, 6.13 to 6.18.16, 6.19 to 6.19.6

Timeline

  • 2026-05-06: disclosed: Initial disclosure of CVE-2026-43150
  • 2026-05-06: advisory
  • 2026-03-04: patched: Fix committed to stable kernel trees

References

Related threats