CVE Database
/

CVE-2026-43055

Back to search

CVE-2026-43055

Published: May 1, 2026

Modified: May 11, 2026

PUBLISHED

CVSS v3.1

7.5

HIGH

Description

In the Linux kernel, the following vulnerability has been resolved: scsi: target: file: Use kzalloc_flex for aio_cmd The target_core_file doesn't initialize the aio_cmd->iocb for the ki_write_stream. When a write command fd_execute_rw_aio() is executed, we may get a bogus ki_write_stream value, causing unintended write failure status when checking iocb->ki_write_stream > max_write_streams in the block device. Let's just use kzalloc_flex when allocating the aio_cmd and let ki_write_stream=0 to fix this issue.

VendorProductVersions

Linux

Linux

affected
732f25a2895a8c1c54fb56544f0b1e23770ef4d7 - < ce54802fe6bb78eb0feffc66fed6a45d41ffc3ab
affected
732f25a2895a8c1c54fb56544f0b1e23770ef4d7 - < 4eaff1728d0e69b95933412241bbccf4f797dba8
affected
732f25a2895a8c1c54fb56544f0b1e23770ef4d7 - < 01f784fc9d0ab2a6dac45ee443620e517cb2a19b

Linux

Linux

affected
6.16
unaffected
0 - < 6.16
unaffected
6.18.22 - <= 6.18.*
unaffected
6.19.12 - <= 6.19.*
unaffected
7.0 - <= *

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector

Network

Attack Complexity

Low

Privileges Required

None

User Interaction

None

Scope

Unchanged

Confidentiality

None

Integrity

None

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now
CVE-2026-43055 | HIGH (7.5) - Security Vulnerability | QwikSec