CVE-2026-43098

medium Red Hat
EPSS Score
0.0%
Exploitation probability in 30 days
Top 95% most likely to be exploited
Published: May 6, 2026 (8 days ago)
Last Modified: May 6, 2026
Vendor: Red Hat
Source: REDHAT

Description

A flaw was found in the Linux kernel's Near Field Communication (NFC) subsystem, specifically within the s3fwrn5 driver. This vulnerability occurs when the driver attempts to consume bytes into a receive buffer (recv_skb) without ensuring a new buffer is allocated if the previous one was delivered. If the allocation of a new buffer fails, the `recv_skb` pointer can become NULL, leading to a NULL dereference during subsequent operations. A local attacker could exploit this memory corruption vulnerability to cause a system crash, resulting in a Denial of Service (DoS).

CWE

CWE-476

Affected Products

Red Hat Enterprise Linux 10Red Hat Enterprise Linux 6Red Hat Enterprise Linux 7Red Hat Enterprise Linux 8Red Hat Enterprise Linux 9

References