PT-2026-37537 · Linux+2 · Linux Kernel+2

CVE-2026-43197

·

Published

2026-02-19

·

Updated

2026-08-30

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.19.0
Description An issue exists in the netconsole component where messages passed from the console subsystem are not guaranteed to be nul-terminated. This can lead to out-of-bounds (OOB) reads when the system processes these messages. The issue was identified through KASAN (Kernel Address Sanitizer), a dynamic memory error detector, which detected slab-out-of-bounds reads during the execution of the netconsole write() function. The vulnerability is triggered when the msg variable is processed by functions such as scnprintf() and vsnprintf() without proper termination.
Recommendations Update the Linux kernel to version 6.19.0 or later.

Exploit

Fix

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-85830
BDU:2026-12087
CVE-2026-43197
OESA-2026-2752
OESA-2026-3157
OPENSUSE-SU-2026:20965-1
SUSE-SU-2026:22099-1
SUSE-SU-2026:22112-1
SUSE-SU-2026:22117-1
SUSE-SU-2026:22127-1
USN-8490-1
USN-8490-2
USN-8491-1
USN-8508-1
USN-8545-1
USN-8546-1
USN-8604-1
USN-8605-1
USN-8630-1
USN-8630-2
USN-8630-3
USN-8630-4
USN-8630-5
USN-8656-1

Affected Products

Linuxmint
Linux Kernel
Ubuntu