PT-2026-37580 · Linux · Linux Kernel

CVE-2026-43240

·

Published

2026-03-05

·

Updated

2026-08-19

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the x86 architecture during the kexec process. When a second-stage kernel is booted using a limiting command line, such as mem=<size>, the physical range containing the carried over IMA (Integrity Measurement Architecture) measurement list may fall outside the truncated RAM. This can result in a kernel panic due to a page fault in the ima restore measurement list() function. Failure to carry the measurement list across kexec would lead to attestation failure.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-11713
CVE-2026-43240
OESA-2026-2582
OESA-2026-3157
OPENSUSE-SU-2026:21388-1
OPENSUSE-SU-2026:21555-1
SUSE-SU-2026:22742-1
SUSE-SU-2026:22769-1
SUSE-SU-2026:22809-1
SUSE-SU-2026:22810-1
SUSE-SU-2026:22812-1
SUSE-SU-2026:22835-1
SUSE-SU-2026:22903-1
SUSE-SU-2026:22904-1
SUSE-SU-2026:23066-1
SUSE-SU-2026:23068-1
SUSE-SU-2026:23193-1
SUSE-SU-2026:23194-1
SUSE-SU-2026:23221-1
SUSE-SU-2026:23231-1
SUSE-SU-2026:23237-1
SUSE-SU-2026:23241-1
SUSE-SU-2026:23244-1
SUSE-SU-2026:3130-1
SUSE-SU-2026:3166-1

Affected Products

Linux Kernel