PT-2026-41874 · Linux+2 · Linux Kernel+2
CVE-2026-43492
·
Published
2026-05-19
·
Updated
2026-09-07
CVSS v3.1
8.1
High
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
An integer underflow exists in the
mpi read raw from sgl() function. This occurs when the number of leading zeros in a scatterlist exceeds the nbytes parameter, causing an underflow during subtraction. This condition can be triggered via a KEYCTL PKEY ENCRYPT system call when the out len is larger than the in len and the input buffer consists of zeros. This leads to a Denial of Service (DoS) as the kernel enters an infinite loop, resulting in soft lockup splats.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
DoS
Integer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linuxmint
Linux Kernel
Ubuntu