CVE-2026-43197

Source
https://cve.org/CVERecord?id=CVE-2026-43197
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-43197.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-43197
Downstream
Related
Published
2026-05-06T11:28:04.829Z
Modified
2026-06-24T18:29:28.761460411Z
Severity
  • 9.1 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H CVSS Calculator
Summary
netconsole: avoid OOB reads, msg is not nul-terminated
Details

In the Linux kernel, the following vulnerability has been resolved:

netconsole: avoid OOB reads, msg is not nul-terminated

msg passed to netconsole from the console subsystem is not guaranteed to be nul-terminated. Before recent commit 7eab73b18630 ("netconsole: convert to NBCON console infrastructure") the message would be placed in printksharedpbufs, a static global buffer, so KASAN had harder time catching OOB accesses. Now we see:

printk: console [netcon_ext0] enabled
BUG: KASAN: slab-out-of-bounds in string+0x1f7/0x240
Read of size 1 at addr ffff88813b6d4c00 by task pr/netcon_ext0/594

CPU: 65 UID: 0 PID: 594 Comm: pr/netcon_ext0 Not tainted 6.19.0-11754-g4246fd6547c9
Call Trace:
 kasan_report+0xe4/0x120
 string+0x1f7/0x240
 vsnprintf+0x655/0xba0
 scnprintf+0xba/0x120
 netconsole_write+0x3fe/0xa10
 nbcon_emit_next_record+0x46e/0x860
 nbcon_kthread_func+0x623/0x750

Allocated by task 1:
 nbcon_alloc+0x1ea/0x450
 register_console+0x26b/0xe10
 init_netconsole+0xbb0/0xda0

The buggy address belongs to the object at ffff88813b6d4000
            which belongs to the cache kmalloc-4k of size 4096
The buggy address is located 0 bytes to the right of
            allocated 3072-byte region [ffff88813b6d4000, ffff88813b6d4c00)
Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/43xxx/CVE-2026-43197.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
c62c0a17f9b7398022f9eebe547878033264f81f
Fixed
3126a2f98beaec5a554a1fb31c46db1e8542665e
Fixed
74ab1456eaa3b2eb986138f9e1f4cb37e73b6f58
Fixed
82aec772fca2223bc5774bd9af486fd95766e578

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-43197.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.6.0
Fixed
6.18.16
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
6.19.6

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-43197.json"