CVE Database
/

CVE-2026-43248

Back to search

CVE-2026-43248

Published: May 6, 2026

Modified: May 11, 2026

PUBLISHED

CVSS v3.1

7.8

HIGH

Description

In the Linux kernel, the following vulnerability has been resolved: vhost: move vdpa group bound check to vhost_vdpa Remove duplication by consolidating these here. This reduces the posibility of a parent driver missing them. While we're at it, fix a bug in vdpa_sim where a valid ASID can be assigned to a group equal to ngroups, causing an out of bound write.

VendorProductVersions

Linux

Linux

affected
bda324fd037a6b0d44da5699574ce741ca161bc4 - < ddb57354634b6ba851b79da45f1de42c646f27d0
affected
bda324fd037a6b0d44da5699574ce741ca161bc4 - < 7441d35d14d9a3d66d925d90cb73c75394e6d454
affected
bda324fd037a6b0d44da5699574ce741ca161bc4 - < 406db68f9cb976a8ddfafd631197264f2307e9c9
affected
bda324fd037a6b0d44da5699574ce741ca161bc4 - < cd025c1e876b4e262e71398236a1550486a73ede

Linux

Linux

affected
5.19
unaffected
0 - < 5.19
unaffected
6.12.75 - <= 6.12.*
unaffected
6.18.16 - <= 6.18.*
unaffected
6.19.6 - <= 6.19.*

+1 more versions

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector

Local

Attack Complexity

Low

Privileges Required

Low

User Interaction

None

Scope

Unchanged

Confidentiality

High

Integrity

High

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now