CVE-2026-43089

In the Linux kernel, the following vulnerability has been resolved: xfrm_user: fix info leak in build_mapping() struct xfrm_usersa_id has a one-byte padding hole after the proto field, which ends up never getting set to zero before copying out to userspace. Fix that up by zeroing out the whole structure before setting individual variables.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc5:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc6:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc7:*:*:*:*:*:*

History

01 Jun 2026, 17:17

Type Values Removed Values Added
References
  • () https://git.kernel.org/stable/c/521385cbd50ca9474396d88462fcdfa6489685d9 -
  • () https://git.kernel.org/stable/c/72a8de41c3eb4dcf22bf3b674ea38fb2f75d6f32 -
  • () https://git.kernel.org/stable/c/c2779ae9a3e5a044e5ccd564681511bbbcc5fc0f -

22 May 2026, 19:47

Type Values Removed Values Added
CWE CWE-401
First Time Linux
Linux linux Kernel
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
CPE cpe:2.3:o:linux:linux_kernel:7.0:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc5:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc6:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc7:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc4:*:*:*:*:*:*
References () https://git.kernel.org/stable/c/1beb76b2053b68c491b78370794b8ff63c8f8c02 - () https://git.kernel.org/stable/c/1beb76b2053b68c491b78370794b8ff63c8f8c02 - Patch
References () https://git.kernel.org/stable/c/5a1a4b049ddde41466ccac0daeec326254b133f2 - () https://git.kernel.org/stable/c/5a1a4b049ddde41466ccac0daeec326254b133f2 - Patch
References () https://git.kernel.org/stable/c/700c9622b23c33b5933e6dcea816492c064e4e10 - () https://git.kernel.org/stable/c/700c9622b23c33b5933e6dcea816492c064e4e10 - Patch
References () https://git.kernel.org/stable/c/d3125c541a96fb3c0fc7210112684baf22b6c24d - () https://git.kernel.org/stable/c/d3125c541a96fb3c0fc7210112684baf22b6c24d - Patch
References () https://git.kernel.org/stable/c/f779a6b6cdb6e12baa0663063ac59ab2a8f20c0c - () https://git.kernel.org/stable/c/f779a6b6cdb6e12baa0663063ac59ab2a8f20c0c - Patch

06 May 2026, 10:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-06 10:16

Updated : 2026-06-01 17:17


NVD link : CVE-2026-43089

Mitre link : CVE-2026-43089

CVE.ORG link : CVE-2026-43089


JSON object : View

Products Affected

linux

  • linux_kernel
CWE
CWE-401

Missing Release of Memory after Effective Lifetime