CVE-2026-43055
Published: May 1, 2026
Modified: May 11, 2026
CVSS v3.1
7.5
Description
In the Linux kernel, the following vulnerability has been resolved: scsi: target: file: Use kzalloc_flex for aio_cmd The target_core_file doesn't initialize the aio_cmd->iocb for the ki_write_stream. When a write command fd_execute_rw_aio() is executed, we may get a bogus ki_write_stream value, causing unintended write failure status when checking iocb->ki_write_stream > max_write_streams in the block device. Let's just use kzalloc_flex when allocating the aio_cmd and let ki_write_stream=0 to fix this issue.
| Vendor | Product | Versions |
|---|---|---|
Linux | Linux | affected 732f25a2895a8c1c54fb56544f0b1e23770ef4d7 - < ce54802fe6bb78eb0feffc66fed6a45d41ffc3abaffected 732f25a2895a8c1c54fb56544f0b1e23770ef4d7 - < 4eaff1728d0e69b95933412241bbccf4f797dba8affected 732f25a2895a8c1c54fb56544f0b1e23770ef4d7 - < 01f784fc9d0ab2a6dac45ee443620e517cb2a19b |
Linux | Linux | affected 6.16unaffected 0 - < 6.16unaffected 6.18.22 - <= 6.18.*unaffected 6.19.12 - <= 6.19.*unaffected 7.0 - <= * |
CVSS v3.1 Details
CVSS v3.1 Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now