PT-2026-38948 · Linux · Linux Kernel

CVE-2026-43306

·

Published

2026-01-12

·

Updated

2026-08-25

CVSS v2.0

6.0

Medium

VectorAV:L/AC:H/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A type mismatch occurs in the Linux kernel when CONFIG CFI (Control Flow Integrity, a security mechanism that ensures indirect function calls target the correct function type) is enabled. This happens because the destructor kfunc type does not match the target function bpf crypto ctx release(), which can lead to a CFI failure and a system crash (Oops).
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Incorrect Type Conversion or Cast

Type Confusion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-86148
BDU:2026-11816
CVE-2026-43306
OPENSUSE-SU-2026:21555-1
SUSE-SU-2026:23066-1
SUSE-SU-2026:23068-1
SUSE-SU-2026:23221-1
SUSE-SU-2026:23231-1
SUSE-SU-2026:23237-1

Affected Products

Linux Kernel