CVE-2026-43041

Source
https://cve.org/CVERecord?id=CVE-2026-43041
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-43041.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-43041
Downstream
Published
2026-05-01T14:15:38Z
Modified
2026-08-12T03:30:47Z
Summary
net: qrtr: replace qrtr_tx_flow radix_tree with xarray to fix memory leak
Details

In the Linux kernel, the following vulnerability has been resolved:

net: qrtr: replace qrtr_tx_flow radix_tree with xarray to fix memory leak

__radix_tree_create() allocates and links intermediate nodes into the tree one by one. If a subsequent allocation fails, the already-linked nodes remain in the tree with no corresponding leaf entry. These orphaned internal nodes are never reclaimed because radix_tree_for_each_slot() only visits slots containing leaf values.

The radix_tree API is deprecated in favor of xarray. As suggested by Matthew Wilcox, migrate qrtr_tx_flow from radix_tree to xarray instead of fixing the radix_tree itself [1]. xarray properly handles cleanup of internal nodes — xa_destroy() frees all internal xarray nodes when the qrtr_node is released, preventing the leak.

[1] https://lore.kernel.org/all/20260225071623.41275-1-jiayuan.chen@linux.dev/T/

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/43xxx/CVE-2026-43041.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
5fdeb0d372ab33b4175043a2a4a1730239a217f1
Fixed
f2dd9aaf6e2861337f5835f877a5b2becaf4b015
Fixed
4b75ff0aedd6ade1018ad4a3a9d8336794e36e42
Fixed
ff134cc43972d7ddceff8cfd36cf6b9eaafc00b3
Fixed
0fda873092b541bb5a9b87d728a2429f863f8cfa
Fixed
69402908e277dd164bf8d7c8fd0513c0fac28e9e
Fixed
f2664bc4f0f356f17c2094587a2b3665e3867e44
Fixed
5d2249eefaca59908fe3c264b8eca526424dcfbe
Fixed
2428083101f6883f979cceffa76cd8440751ffe6

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-43041.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.6.0
Fixed
5.10.253
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.203
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.168
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.134
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.81
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.22
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
6.19.12

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-43041.json"