CVE-2026-43442

medium Red Hat
EPSS Score
0.0%
Exploitation probability in 30 days
Top 95% most likely to be exploited
Published: May 8, 2026 (6 days ago)
Last Modified: May 8, 2026
Vendor: Red Hat
Source: REDHAT

Description

A flaw was found in the Linux kernel's io_uring subsystem. An incorrect bounds check for 128-byte Submission Queue Entry (SQE) operations, when IORING_SETUP_SQE_MIXED is used without IORING_SETUP_NO_SQARRAY, allows an unprivileged local user to remap logical SQE positions to arbitrary physical indices. This can lead to an out-of-bounds read, potentially disclosing sensitive information from kernel memory.

CWE

CWE-805

Affected Products

Red Hat Enterprise Linux 10Red Hat Enterprise Linux 6Red Hat Enterprise Linux 7Red Hat Enterprise Linux 8Red Hat Enterprise Linux 9

References