Junglewise Threat Intelligence

CVE-2026-43248: Linux Kernel out-of-bounds write in vhost vDPA subsystem

CVE-2026-43248 · Severity: high · CVSS 7.8 · Published 2026-05-06

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's virtualization components (vDPA) that could allow a local user to cause a system crash or potentially gain unauthorized access. The issue stems from a technical error in how the system handles virtual device groups, which can lead to memory corruption. This affects systems using vDPA for high-performance networking or storage in virtualized environments.

Technical details

An out-of-bounds write vulnerability (CWE-787) exists in the Linux kernel's vDPA (vhost Data Path Acceleration) subsystem, specifically within the vdpa_sim driver. The root cause is a logic error where a valid Address Space Identifier (ASID) could be assigned to a group index equal to 'ngroups', bypassing intended boundary checks. This consolidation of checks into vhost_vdpa addresses the risk of parent drivers missing these validations. A local attacker with low privileges can exploit this via IOCTL calls (VHOST_VDPA_SET_GROUP_ASID) to trigger memory corruption, potentially leading to a denial of service or local privilege escalation. Patches have been released for multiple stable kernel branches including 6.12.75, 6.18.16, and 6.19.6.

Affected products

  • Linux Linux Kernel 5.19 to 6.12.75, 6.13 to 6.18.16, 6.19 to 6.19.6

Timeline

  • 2026-05-06: disclosed
  • 2026-05-06: advisory
  • 2026-03-04: patched: Patches applied to stable branches.

References

Related threats