VDB

CVE-2026-43107

CVE-2026-43107 PUBLISHED

In the Linux kernel, the following vulnerability has been resolved: xfrm: account XFRMA_IF_ID in aevent size calculation xfrm_get_ae() allocates the reply skb with xfrm_aevent_msgsize(), then build_aevent() appends attributes including XFRMA_IF_ID when x->if_id is set. xfrm_aevent_msgsize() does not include space for XFRMA_IF_ID. For states with if_id, build_aevent() can fail with -EMSGSIZE and hit BUG_ON(err < 0) in xfrm_get_ae(), turning a malformed netlink interaction into a kernel panic. Account XFRMA_IF_ID in the size calculation unconditionally and replace the BUG_ON with normal error unwinding.

EPSS 0.01% · 2.2th percentile

Risk Scores

EPSS Score
0.01%
2.2th percentile

Affected Products

VendorProductVersions
linuxlinux_kernel4.19, 4.19, 4.19
LinuxLinux7e6526404adedf079279aa7aa11722deaca8fe2e, 7e6526404adedf079279aa7aa11722deaca8fe2e, 4.19

Timeline

  • May 6, 2026 CVE Published
  • May 6, 2026 Security Advisory
  • May 11, 2026 CVE Updated
  • May 18, 2026 EPSS Score
  • May 19, 2026 EPSS Score
  • May 20, 2026 EPSS Score
  • May 21, 2026 EPSS Score
  • May 22, 2026 EPSS Score
  • May 23, 2026 EPSS Score
  • May 24, 2026 EPSS Score
  • May 25, 2026 EPSS Score
  • May 26, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›