Junglewise Threat Intelligence

CVE-2026-43244: Linux Kernel KCM denial of service in kcm_sendmsg

CVE-2026-43244 · Severity: medium · CVSS 5.5 · Published 2026-05-06

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's Kernel Connection Multiplexor (KCM) component, which is used to improve networking performance by multiplexing messages. Under specific error conditions during data transmission, the system can enter an unstable state that triggers internal kernel warnings. This could potentially be exploited by a local attacker to cause a system crash or denial of service, impacting operational availability.

Technical details

A vulnerability in the Linux kernel's KCM (Kernel Connection Multiplexor) module occurs when kcm_sendmsg() encounters a partial send error (such as -EFAULT) after allocating a new socket buffer (skb) to accommodate MAX_SKB_FRAGS. If the data copy fails, the newly allocated skb remains in the frag_list with zero fragments. For SOCK_SEQPACKET, subsequent zero-length writes can complete the message and queue it, causing kcm_write_msgs() to trigger a WARN_ON when it encounters the empty skb. This is a missing cleanup issue similar to one previously fixed in TCP. The fix introduces tracking of the predecessor skb (frag_prev) to allow O(1) unlinking and freeing of empty buffers during error handling.

Affected products

  • Linux Linux Kernel 4.6 to 6.12.75, 6.13 to 6.18.16, 6.19 to 6.19.6, 7.0-rc1

Timeline

  • 2026-02-19: patched: Initial patch submitted by Jiayuan Chen
  • 2026-05-06: disclosed: CVE-2026-43244 published

References

Related threats