CVE-2026-43058

In the Linux kernel, the following vulnerability has been resolved: media: vidtv: fix pass-by-value structs causing MSAN warnings vidtv_ts_null_write_into() and vidtv_ts_pcr_write_into() take their argument structs by value, causing MSAN to report uninit-value warnings. While only vidtv_ts_null_write_into() has triggered a report so far, both functions share the same issue. Fix by passing both structs by const pointer instead, avoiding the stack copy of the struct along with its MSAN shadow and origin metadata. The functions do not modify the structs, which is enforced by the const qualifier.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

History

01 Jun 2026, 17:17

Type Values Removed Values Added
References
  • () https://git.kernel.org/stable/c/a73f84a30975e6c4ae06efd500d31c82564dba10 -
  • () https://git.kernel.org/stable/c/a876d72ceba7fe5444005239f363c105767e0ecf -
  • () https://git.kernel.org/stable/c/c034d8094fee474eb94142c17643eee2919079b7 -

22 May 2026, 12:05

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
CWE CWE-476
CPE cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
References () https://git.kernel.org/stable/c/1b2820c8a9887981634020db19f1a2425558b88e - () https://git.kernel.org/stable/c/1b2820c8a9887981634020db19f1a2425558b88e - Patch
References () https://git.kernel.org/stable/c/57b01d945ed68cebe486d495dadc4901a96d3aaa - () https://git.kernel.org/stable/c/57b01d945ed68cebe486d495dadc4901a96d3aaa - Patch
References () https://git.kernel.org/stable/c/5f8e73bde67e931468bc2a1860d78d72f0c6ba41 - () https://git.kernel.org/stable/c/5f8e73bde67e931468bc2a1860d78d72f0c6ba41 - Patch
References () https://git.kernel.org/stable/c/6d75a9ec5bdb8cf8382eaf8f8fe831ba7d58a9d4 - () https://git.kernel.org/stable/c/6d75a9ec5bdb8cf8382eaf8f8fe831ba7d58a9d4 - Patch
References () https://git.kernel.org/stable/c/be57e52e27c7cbfb400a8f255e475cbcff242baa - () https://git.kernel.org/stable/c/be57e52e27c7cbfb400a8f255e475cbcff242baa - Patch
References () https://git.kernel.org/stable/c/e3957eb26a3d570aefc6bb184fa8b8a1e9a4e508 - () https://git.kernel.org/stable/c/e3957eb26a3d570aefc6bb184fa8b8a1e9a4e508 - Patch
First Time Linux
Linux linux Kernel

02 May 2026, 07:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-02 07:16

Updated : 2026-06-01 17:17


NVD link : CVE-2026-43058

Mitre link : CVE-2026-43058

CVE.ORG link : CVE-2026-43058


JSON object : View

Products Affected

linux

  • linux_kernel
CWE
CWE-476

NULL Pointer Dereference