CVE-2026-43032

In the Linux kernel, the following vulnerability has been resolved: NFC: pn533: bound the UART receive buffer pn532_receive_buf() appends every incoming byte to dev->recv_skb and only resets the buffer after pn532_uart_rx_is_frame() recognizes a complete frame. A continuous stream of bytes without a valid PN532 frame header therefore keeps growing the skb until skb_put_u8() hits the tail limit. Drop the accumulated partial frame once the fixed receive buffer is full so malformed UART traffic cannot grow the skb past PN532_UART_SKB_BUFF_LEN.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc5:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc6:*:*:*:*:*:*

History

08 May 2026, 18:39

Type Values Removed Values Added
First Time Linux linux Kernel
Linux
CWE NVD-CWE-noinfo
References () https://git.kernel.org/stable/c/23e925183db26cd322597679669ad29d70ed2ada - () https://git.kernel.org/stable/c/23e925183db26cd322597679669ad29d70ed2ada - Patch
References () https://git.kernel.org/stable/c/2c1fadd221b21d8038acfe6a0f56291881d5ff76 - () https://git.kernel.org/stable/c/2c1fadd221b21d8038acfe6a0f56291881d5ff76 - Patch
References () https://git.kernel.org/stable/c/30fe3f5f6494f827d812ff179f295a8e532709d6 - () https://git.kernel.org/stable/c/30fe3f5f6494f827d812ff179f295a8e532709d6 - Patch
References () https://git.kernel.org/stable/c/3adca9be14bf36b927193f05f5aea35a1a90e913 - () https://git.kernel.org/stable/c/3adca9be14bf36b927193f05f5aea35a1a90e913 - Patch
References () https://git.kernel.org/stable/c/8bedf1dd5640ac8997bff00bbefe241b438df397 - () https://git.kernel.org/stable/c/8bedf1dd5640ac8997bff00bbefe241b438df397 - Patch
References () https://git.kernel.org/stable/c/ad2f60de5045bfb5d20ea468a97c8760c6a3a4f8 - () https://git.kernel.org/stable/c/ad2f60de5045bfb5d20ea468a97c8760c6a3a4f8 - Patch
References () https://git.kernel.org/stable/c/cf2ff10183204349edfd6b972e189375fc5f1fb0 - () https://git.kernel.org/stable/c/cf2ff10183204349edfd6b972e189375fc5f1fb0 - Patch
References () https://git.kernel.org/stable/c/f48ab6ee654ecc350434e4566bc785773f412b7e - () https://git.kernel.org/stable/c/f48ab6ee654ecc350434e4566bc785773f412b7e - Patch
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
CPE cpe:2.3:o:linux:linux_kernel:7.0:rc6:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc5:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc1:*:*:*:*:*:*

01 May 2026, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-01 15:16

Updated : 2026-05-08 18:39


NVD link : CVE-2026-43032

Mitre link : CVE-2026-43032

CVE.ORG link : CVE-2026-43032


JSON object : View

Products Affected

linux

  • linux_kernel