CVE-2026-43256

HIGH EPSS 2.9%
Published May 6, 20261mo ago · Modified Jun 17, 20262w ago
7.8 CVSS 3.1
High
Find Similar
Published May 6, 2026 1mo ago
Last Modified Jun 17, 2026 2w ago

Description

In the Linux kernel, the following vulnerability has been resolved: media: qcom: camss: vfe: Fix out-of-bounds access in vfe_isr_reg_update() vfe_isr() iterates using MSM_VFE_IMAGE_MASTERS_NUM(7) as the loop bound and passes the index to vfe_isr_reg_update(). However, vfe->line[] array is defined with VFE_LINE_NUM_MAX(4): struct vfe_line line[VFE_LINE_NUM_MAX]; When index is 4, 5, 6, the access to vfe->line[line_id] exceeds the array bounds and resulting in out-of-bounds memory access. Fix this by using separate loops for output lines and write masters.

CVSS Details

Base Score
7.8
Exploitability
1.8
Impact
5.9
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector Local
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality High
Integrity High
Availability High

Threat Intelligence

EPSS Exploit Probability
2.9% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Weaknesses 1

CWE-125 Out-of-bounds Read Memory Safety

Affected Products 5

VendorProductVersionRange
linuxlinux_kernel*≥5.18  –  <6.1.167
linuxlinux_kernel*≥6.2  –  <6.6.128
linuxlinux_kernel*≥6.7  –  <6.12.75
linuxlinux_kernel*≥6.13  –  <6.18.16
linuxlinux_kernel*≥6.19  –  <6.19.6

References 6

  • git.kernel.org https://git.kernel.org/stable/c/0c074e80921fd18984b75836730d76c768c84f65
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/1b103307df6d461a0731be25aca69ad0335b0933
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/d965919af524e68cb2ab1a685872050ad2ee933d
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/e6cbf765686fb6c1d8f2530b3daf6c66efc92f5d
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/e7a38ecda2498e7ce998793ac2a46ca47317635d
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/fade67c88870f497a13ed450ba01f7236c92dd9b
    Patch

Remediation

  • git.kernel.org https://git.kernel.org/stable/c/0c074e80921fd18984b75836730d76c768c84f65
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/1b103307df6d461a0731be25aca69ad0335b0933
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/d965919af524e68cb2ab1a685872050ad2ee933d
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/e6cbf765686fb6c1d8f2530b3daf6c66efc92f5d
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/e7a38ecda2498e7ce998793ac2a46ca47317635d
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/fade67c88870f497a13ed450ba01f7236c92dd9b
    Patch