PT-2026-41874 · Linux+2 · Linux Kernel+2

CVE-2026-43492

·

Published

2026-05-19

·

Updated

2026-09-07

CVSS v3.1

8.1

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An integer underflow exists in the mpi read raw from sgl() function. This occurs when the number of leading zeros in a scatterlist exceeds the nbytes parameter, causing an underflow during subtraction. This condition can be triggered via a KEYCTL PKEY ENCRYPT system call when the out len is larger than the in len and the input buffer consists of zeros. This leads to a Denial of Service (DoS) as the kernel enters an infinite loop, resulting in soft lockup splats.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-86975
CVE-2026-43492
ECHO-6A54-7684-DEBA
OESA-2026-2493
OESA-2026-2494
OESA-2026-2495
OPENSUSE-SU-2026:10859-1
OPENSUSE-SU-2026:21388-1
SUSE-SU-2026:22521-1
SUSE-SU-2026:22522-1
SUSE-SU-2026:22665-1
SUSE-SU-2026:22666-1
SUSE-SU-2026:22742-1
SUSE-SU-2026:22769-1
SUSE-SU-2026:22812-1
SUSE-SU-2026:22835-1
SUSE-SU-2026:2799-1
SUSE-SU-2026:2800-1
SUSE-SU-2026:2914-1
USN-8566-1
USN-8567-1
USN-8568-1
USN-8569-1
USN-8574-1
USN-8574-2
USN-8574-3
USN-8593-1
USN-8595-1
USN-8595-2
USN-8595-3
USN-8596-1
USN-8603-1
USN-8606-1
USN-8607-1
USN-8608-1
USN-8609-1
USN-8618-1
USN-8619-1
USN-8663-1
USN-8664-1
USN-8665-1
USN-8728-1

Affected Products

Linuxmint
Linux Kernel
Ubuntu