CVE-2026-43121

medium Red Hat
Published: May 6, 2026 (8 days ago)
Last Modified: May 6, 2026
Vendor: Red Hat
Source: REDHAT

Description

A flaw was found in the `io_uring/zcrx` component of the Linux kernel. This vulnerability involves a race condition where two operations can manipulate the same memory counter simultaneously without proper synchronization. This can lead to a memory object being freed twice, followed by an out-of-bounds write. Such memory corruption could allow a local attacker to escalate privileges or execute arbitrary code, potentially compromising the system.

CWE

CWE-366

Affected Products

Red Hat Enterprise Linux 10Red Hat Enterprise Linux 6Red Hat Enterprise Linux 7Red Hat Enterprise Linux 8Red Hat Enterprise Linux 9

References