Junglewise Threat Intelligence

CVE-2026-43281: Linux Kernel out-of-bounds access in mailbox subsystem

CVE-2026-43281 · Severity: high · CVSS 7.1 · Published 2026-05-06

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's mailbox subsystem could allow a local attacker to cause a system crash or potentially access sensitive memory. The mailbox component is responsible for communication between different processors or hardware modules within a system. This issue occurs when certain hardware configuration files (device trees) contain unexpected values, leading to an out-of-bounds memory access.

Technical details

The vulnerability is a CWE-125 (Out-of-bounds Read) located in the mailbox framework, specifically within the fw_mbox_index_xlate() and of_mbox_index_xlate() functions in drivers/mailbox/mailbox.c. While documentation specifies that '#mbox-cells' should be at least 1, some device trees use a value of 0. When a mailbox controller lacks custom translation pointers (fw_xlate or of_xlate), the kernel falls back to default functions that fail to validate the number of arguments (nargs/args_count) before accessing the args array. A local attacker with the ability to trigger mailbox channel requests could exploit this to read out-of-bounds kernel memory or cause a denial-of-service (kernel oops). Patches have been released across multiple stable kernel branches.

Affected products

  • Linux Linux Kernel 3.18.1 to 6.1.167, 6.2 to 6.6.130, 6.7 to 6.12.77, 6.13 to 6.18.16, 6.19 to 6.19.6

Timeline

  • 2026-05-06: advisory: Initial NVD publication
  • 2026-03-13: patched: Fix committed to stable kernel tree

References

Related threats