CVE-2026-43333

MEDIUM EPSS 2.4%
Published May 8, 20261mo ago · Modified Jun 17, 20261w ago
5.5 CVSS 3.1
Medium
Find Similar
Published May 8, 2026 1mo ago
Last Modified Jun 17, 2026 1w ago

Description

In the Linux kernel, the following vulnerability has been resolved: bpf: reject direct access to nullable PTR_TO_BUF pointers check_mem_access() matches PTR_TO_BUF via base_type() which strips PTR_MAYBE_NULL, allowing direct dereference without a null check. Map iterator ctx->key and ctx->value are PTR_TO_BUF | PTR_MAYBE_NULL. On stop callbacks these are NULL, causing a kernel NULL dereference. Add a type_may_be_null() guard to the PTR_TO_BUF branch, matching the existing PTR_TO_BTF_ID pattern.

CVSS Details

Base Score
5.5
Exploitability
1.8
Impact
3.6
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Vector Local
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality None
Integrity None
Availability High

Threat Intelligence

EPSS Exploit Probability
2.4% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Weaknesses 1

CWE-476 NULL Pointer Dereference Memory Safety

Affected Products 12

VendorProductVersionRange
linuxlinux_kernel*≥5.15.37  –  <5.15.203
linuxlinux_kernel*≥5.16.11  –  <6.1.168
linuxlinux_kernel*≥6.2  –  <6.6.134
linuxlinux_kernel*≥6.7  –  <6.12.81
linuxlinux_kernel*≥6.13  –  <6.18.22
linuxlinux_kernel*≥6.19  –  <6.19.12
linuxlinux_kernel7.0any
linuxlinux_kernel7.0any
linuxlinux_kernel7.0any
linuxlinux_kernel7.0any
linuxlinux_kernel7.0any
linuxlinux_kernel7.0any

References 7

  • git.kernel.org https://git.kernel.org/stable/c/10bc4a4dcded509c5d5c67d497900c3922c604cd
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/21a10c06ffae24cb01fd174a7ab7736001d2ea56
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/4f6c99dc0420f1a3d671c1b8ab8a7ac84d9cba09
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/63276547debc4d8a73eefb2c5273b2a905c961b0
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/70abd9d118da2f56beb4ec22e3a29becae373535
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/8755066f7bd0f4ac46a29d1708c7b20894539252
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/b0db1accbc7395657c2b79db59fa9fae0d6656f3
    Patch

Remediation

  • git.kernel.org https://git.kernel.org/stable/c/10bc4a4dcded509c5d5c67d497900c3922c604cd
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/21a10c06ffae24cb01fd174a7ab7736001d2ea56
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/4f6c99dc0420f1a3d671c1b8ab8a7ac84d9cba09
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/63276547debc4d8a73eefb2c5273b2a905c961b0
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/70abd9d118da2f56beb4ec22e3a29becae373535
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/8755066f7bd0f4ac46a29d1708c7b20894539252
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/b0db1accbc7395657c2b79db59fa9fae0d6656f3
    Patch