CVE 7.8 HIGH

vhost: move vdpa group bound check to vhost_vdpa_CVE-2026-43248

7.8 / 10
HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Description

In the Linux kernel, the following vulnerability has been resolved:

vhost: move vdpa group bound check to vhost_vdpa

Remove duplication by consolidating these here. This reduces the
posibility of a parent driver missing them.

While we're at it, fix a bug in vdpa_sim where a valid ASID can be
assigned to a group equal to ngroups, causing an out of bound write.

Basic Information

ID CVE-2026-43248
Source Linux
Published May 6, 2026 at 11:28
Modified May 8, 2026 at 12:41

Affected Product

Vendor Linux
Product Linux
Version bda324fd037a6b0d44da5699574ce741ca161bc4
Affected Versions Linux Linux bda324fd037a6b0d44da5699574ce741ca161bc4
Linux Linux bda324fd037a6b0d44da5699574ce741ca161bc4
Linux Linux bda324fd037a6b0d44da5699574ce741ca161bc4
Linux Linux bda324fd037a6b0d44da5699574ce741ca161bc4
Linux Linux 5.19

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.