cbcvebase.
CVE-2026-43093
published 2026-05-06

CVE-2026-43093: In the Linux kernel, the following vulnerability has been resolved: xsk: tighten UMEM headroom validation to account for tailroom and min frame The current…

PriorityP341high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.13%
3.0th percentile
In the Linux kernel, the following vulnerability has been resolved: xsk: tighten UMEM headroom validation to account for tailroom and min frame The current headroom validation in xdp_umem_reg() could leave us with insufficient space dedicated to even receive minimum-sized ethernet frame. Furthermore if multi-buffer would come to play then skb_shared_info stored at the end of XSK frame would be corrupted. HW typically works with 128-aligned sizes so let us provide this value as bare minimum. Multi-buffer setting is known later in the configuration process so besides accounting for 128 bytes, let us also take care of tailroom space upfront.

Affected

62 ranges· showing 25
VendorProductVersion rangeFixed in
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 4.19.118 < 4.204.20
linuxlinux>= 5.4.35 < 5.55.5
linuxlinux>= 5.6.7 < 5.75.7
linuxlinux>= 99e3a236dd43d06c65af0a2ef9cb44306aef6e02 < 5f123bc278bf4e3283d8606321bebbfd299f43845f123bc278bf4e3283d8606321bebbfd299f4384
linuxlinux>= 99e3a236dd43d06c65af0a2ef9cb44306aef6e02 < 1a6051cd7e3e4c54ff3854a43b638b9292af5e671a6051cd7e3e4c54ff3854a43b638b9292af5e67
linuxlinux>= 99e3a236dd43d06c65af0a2ef9cb44306aef6e02 < 8769708add9eadeea8041a9761771bb715a871048769708add9eadeea8041a9761771bb715a87104
linuxlinux>= 99e3a236dd43d06c65af0a2ef9cb44306aef6e02 < a03975beb9f6af0d8ac051e30b2abeabe618414fa03975beb9f6af0d8ac051e30b2abeabe618414f
linuxlinux>= 99e3a236dd43d06c65af0a2ef9cb44306aef6e02 < 0ec4d3f6e6934deb843b561ae048cd17218e5ad10ec4d3f6e6934deb843b561ae048cd17218e5ad1
linuxlinux>= 99e3a236dd43d06c65af0a2ef9cb44306aef6e02 < 9ea6ba4f3195dcba6e8b3e7b2e748593b7cafb129ea6ba4f3195dcba6e8b3e7b2e748593b7cafb12
linuxlinux>= 99e3a236dd43d06c65af0a2ef9cb44306aef6e02 < 6523bc1b40e69301f24c14338b762af4739d6d396523bc1b40e69301f24c14338b762af4739d6d39
linuxlinux>= 99e3a236dd43d06c65af0a2ef9cb44306aef6e02 < a315e022a72d95ef5f1d4e58e903cb492b0ad931a315e022a72d95ef5f1d4e58e903cb492b0ad931
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 4.19.118 < 4.204.20
linuxlinux_kernel>= 5.4.35 < 5.55.5
linuxlinux_kernel>= 5.6.7 < 5.75.7
linuxlinux_kernel>= 5.7.1 < 6.6.1366.6.136
linuxlinux_kernel>= 6.13 < 6.18.246.18.24
linuxlinux_kernel>= 6.19 < 6.19.146.19.14
linuxlinux_kernel>= 6.7 < 6.12.836.12.83

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_ubuntu7.1HIGH
vendor_redhat7.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.