PT-2026-37417 · Linux+2 · Linux Kernel+2

CVE-2026-43107

·

Published

2026-05-06

·

Updated

2026-08-25

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A flaw exists in the xfrm component where the xfrm get ae() function allocates a reply socket buffer (skb) using xfrm aevent msgsize(), but the build aevent() function may append additional attributes, such as XFRMA IF ID, when x->if id is set. Because xfrm aevent msgsize() fails to account for the space required by XFRMA IF ID, the process can fail with an -EMSGSIZE error. This triggers a BUG ON(err < 0) condition in xfrm get ae(), which can lead to a kernel panic resulting from a malformed netlink interaction.
Recommendations Update the kernel to a version where XFRMA IF ID is unconditionally included in the size calculation and the BUG ON macro is replaced with normal error unwinding.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-85869
CVE-2026-43107
OESA-2026-2675
OESA-2026-2676
OPENSUSE-SU-2026:21388-1
SUSE-SU-2026:22521-1
SUSE-SU-2026:22522-1
SUSE-SU-2026:22665-1
SUSE-SU-2026:22666-1
SUSE-SU-2026:22742-1
SUSE-SU-2026:22769-1
SUSE-SU-2026:22812-1
SUSE-SU-2026:22835-1
SUSE-SU-2026:2799-1
SUSE-SU-2026:2800-1
USN-8567-1
USN-8574-1
USN-8574-2
USN-8574-3
USN-8595-1
USN-8595-2
USN-8595-3
USN-8596-1
USN-8606-1
USN-8607-1
USN-8608-1
USN-8609-1
USN-8619-1
USN-8665-1

Affected Products

Linuxmint
Linux Kernel
Ubuntu