Junglewise Threat Intelligence

CVE-2026-43197: Linux Kernel out-of-bounds read in netconsole

CVE-2026-43197 · Severity: critical · CVSS 9.1 · Published 2026-05-06

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability exists in the Linux kernel's netconsole feature, which is used to send system log messages over a network. Due to a technical error in how messages are handled, an attacker could potentially trigger a system crash or gain access to sensitive information stored in the system's memory. This could lead to service outages or data exposure on affected servers.

Technical details

An out-of-bounds (OOB) read vulnerability exists in the netconsole driver (drivers/net/netconsole.c) within the send_msg_no_fragmentation function. The root cause is that messages passed from the console subsystem are not NUL-terminated, but were being processed by scnprintf using a %s format specifier. This flaw was made more detectable/exploitable following the conversion to the NBCON console infrastructure, which moved buffers from static global memory to the slab allocator. An attacker can trigger this OOB read, potentially leading to a kernel panic (DoS) or disclosure of adjacent slab memory. Patches have been released for multiple stable kernel branches.

Affected products

  • Linux Linux Kernel 6.6 to 6.18.16, 6.19 to 6.19.6, 7.0-rc1

Timeline

  • 2026-02-19: other: Patch authored
  • 2026-05-06: disclosed: CVE published
  • 2026-05-11: advisory: NVD entry updated with analysis

References

Related threats