CVE-2026-43206

Source
https://cve.org/CVERecord?id=CVE-2026-43206
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-43206.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-43206
Downstream
Related
Published
2026-05-06T11:28:10.937Z
Modified
2026-06-11T12:29:14.672691360Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
drm/amdkfd: Fix out-of-bounds write in kfd_event_page_set()
Details

In the Linux kernel, the following vulnerability has been resolved:

drm/amdkfd: Fix out-of-bounds write in kfdeventpage_set()

The kfdeventpageset() function writes KFDSIGNALEVENTLIMIT * 8 bytes via memset without checking the buffer size parameter. This allows unprivileged userspace to trigger an out-of bounds kernel memory write by passing a small buffer, leading to potential privilege escalation.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/43xxx/CVE-2026-43206.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
0fc8011f89feb8b2c3008583b777d097e1974660
Fixed
3e04bc310d80b46eaf481f1fefcbcb37a187412d
Fixed
de8d7a25cd2eb5875b1d8d4fbc7fe4b4138b781f
Fixed
b4034442cb090e4a980bdcc1540948606cbc951b
Fixed
4857c37c7ba9aa38b9a4c694e8bd8d0091c87940
Fixed
75fb57efdd7863fffbc39db23e9cad7aafda26ed
Fixed
bfcd6b53e1f4feb182952f4ff9a137c36ceaf20b
Fixed
4e72f419e4ed44cb3b60506752d8688c20a60a9b
Fixed
8a70a26c9f34baea6c3199a9862ddaff4554a96d

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-43206.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.17.0
Fixed
5.10.252
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.202
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.165
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.128
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.75
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.16
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
6.19.6

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-43206.json"