CVE-2026-43272

In the Linux kernel, the following vulnerability has been resolved: ring-buffer: Fix possible dereference of uninitialized pointer There is a pointer head_page in rb_meta_validate_events() which is not initialized at the beginning of a function. This pointer can be dereferenced if there is a failure during reader page validation. In this case the control is passed to "invalid" label where the pointer is dereferenced in a loop. To fix the issue initialize orig_head and head_page before calling rb_validate_buffer. Found by Linux Verification Center (linuxtesting.org) with SVACE.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

History

08 May 2026, 20:00

Type Values Removed Values Added
CPE cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
First Time Linux linux Kernel
Linux
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
CWE CWE-476
References () https://git.kernel.org/stable/c/bc77986f3cb7476637052edf2d87137fa39f153d - () https://git.kernel.org/stable/c/bc77986f3cb7476637052edf2d87137fa39f153d - Patch
References () https://git.kernel.org/stable/c/d9942396845fef2369478c157b26738fe07142f6 - () https://git.kernel.org/stable/c/d9942396845fef2369478c157b26738fe07142f6 - Patch
References () https://git.kernel.org/stable/c/f1547779402c4cd67755c33616b7203baa88420b - () https://git.kernel.org/stable/c/f1547779402c4cd67755c33616b7203baa88420b - Patch

06 May 2026, 12:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-06 12:16

Updated : 2026-05-08 20:00


NVD link : CVE-2026-43272

Mitre link : CVE-2026-43272

CVE.ORG link : CVE-2026-43272


JSON object : View

Products Affected

linux

  • linux_kernel
CWE
CWE-476

NULL Pointer Dereference