In the Linux kernel, the following vulnerability has been resolved:
vhost: move vdpa group bound check to vhost_vdpa
Remove duplication by consolidating these here. This reduces the
posibility of a parent driver missing them.
While we're at it, fix a bug in vdpa_sim where a valid ASID can be
assigned to a group equal to ngroups, causing an out of bound write.
References
Configurations
Configuration 1 (hide)
|
History
11 May 2026, 13:14
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Linux linux Kernel
Linux |
|
| CWE | CWE-787 | |
| CPE | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | |
| References | () https://git.kernel.org/stable/c/406db68f9cb976a8ddfafd631197264f2307e9c9 - Patch | |
| References | () https://git.kernel.org/stable/c/7441d35d14d9a3d66d925d90cb73c75394e6d454 - Patch | |
| References | () https://git.kernel.org/stable/c/cd025c1e876b4e262e71398236a1550486a73ede - Patch | |
| References | () https://git.kernel.org/stable/c/ddb57354634b6ba851b79da45f1de42c646f27d0 - Patch |
08 May 2026, 13:16
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.8 |
06 May 2026, 12:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-06 12:16
Updated : 2026-05-11 13:14
NVD link : CVE-2026-43248
Mitre link : CVE-2026-43248
CVE.ORG link : CVE-2026-43248
JSON object : View
Products Affected
linux
- linux_kernel
CWE
CWE-787
Out-of-bounds Write
