Junglewise Threat Intelligence

CVE-2026-43208: Linux kernel out-of-bounds write in set_rps_cpu

CVE-2026-43208 · Severity: critical · CVSS 9.8 · Published 2026-05-06

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability has been identified in the Linux kernel's networking component that handles how incoming data traffic is distributed across processor cores. An error in how the system tracks network data flows can lead to memory corruption or system crashes. If exploited, this could allow an attacker to disrupt network services or potentially gain unauthorized access to the system.

Technical details

An out-of-bounds write vulnerability (CWE-787) exists in the Linux kernel's networking stack within the RPS (Receive Packet Steering) implementation. The issue stems from `set_rps_cpu()` incorrectly assuming that RPS tables for different receive queues are of uniform size and remain static. By using a `flow_id` previously computed by `get_rps_cpu()` instead of recalculating it for the specific target table, the kernel may perform out-of-bounds memory accesses. This can be triggered by network traffic under specific RPS configurations, leading to system instability or arbitrary code execution. Patches have been released for multiple stable kernel branches including 6.18.y and 6.19.y.

Affected products

  • Linux Linux Kernel 6.18 to 6.18.16, 6.19 to 6.19.6, 7.0-rc1

Timeline

  • 2026-02-20: other: Patch authored by Eric Dumazet
  • 2026-05-06: disclosed: CVE published by kernel.org
  • 2026-05-11: advisory: NVD enrichment and analysis completed

References

Related threats