CVE-2026-43109

MEDIUM EPSS 1.7%
Published May 6, 20261mo ago · Modified Jun 17, 20261w ago
5.5 CVSS 3.1
Medium
Find Similar
Published May 6, 2026 1mo ago
Last Modified Jun 17, 2026 1w ago

Description

In the Linux kernel, the following vulnerability has been resolved: x86: shadow stacks: proper error handling for mmap lock 김영민 reports that shstk_pop_sigframe() doesn't check for errors from mmap_read_lock_killable(), which is a silly oversight, and also shows that we haven't marked those functions with "__must_check", which would have immediately caught it. So let's fix both issues.

CVSS Details

Base Score
5.5
Exploitability
1.8
Impact
3.6
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Vector Local
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality None
Integrity None
Availability High

Threat Intelligence

EPSS Exploit Probability
1.7% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Affected Products 9

VendorProductVersionRange
linuxlinux_kernel*≥6.6  –  <6.18.24
linuxlinux_kernel*≥6.19  –  <6.19.14
linuxlinux_kernel7.0any
linuxlinux_kernel7.0any
linuxlinux_kernel7.0any
linuxlinux_kernel7.0any
linuxlinux_kernel7.0any
linuxlinux_kernel7.0any
linuxlinux_kernel7.0any

References 5

  • git.kernel.org https://git.kernel.org/stable/c/1a30468eff661937d978495644d2e5ebfeef5ce6
  • git.kernel.org https://git.kernel.org/stable/c/262b6d38a81d51b135db81e1f30c13d30e38feee
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/52f657e34d7b21b47434d9d8b26fa7f6778b63a0
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/c64cebcc5c4f223dbcbe7dcdf74908fc092a0aa4
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/c79cf42321600e931933e11f94aba8b245d4cd66

Remediation

  • git.kernel.org https://git.kernel.org/stable/c/262b6d38a81d51b135db81e1f30c13d30e38feee
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/52f657e34d7b21b47434d9d8b26fa7f6778b63a0
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/c64cebcc5c4f223dbcbe7dcdf74908fc092a0aa4
    Patch