CVE-2026-43248

Published: Mag 06, 2026 Last Modified: Mag 06, 2026
ExploitDB:
Other exploit source:
Google Dorks:

Description

AI Translation Available

In the Linux kernel, the following vulnerability has been resolved:

vhost: move vdpa group bound check to vhost_vdpa

Remove duplication by consolidating these here. This reduces the
posibility of a parent driver missing them.

While we're at it, fix a bug in vdpa_sim where a valid ASID can be
assigned to a group equal to ngroups, causing an out of bound write.

https://git.kernel.org/stable/c/406db68f9cb976a8ddfafd631197264f2307e9c9
https://git.kernel.org/stable/c/7441d35d14d9a3d66d925d90cb73c75394e6d454
https://git.kernel.org/stable/c/cd025c1e876b4e262e71398236a1550486a73ede
https://git.kernel.org/stable/c/ddb57354634b6ba851b79da45f1de42c646f27d0