cbcvebase.
CVE-2026-43206
published 2026-05-06

CVE-2026-43206: In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Fix out-of-bounds write in kfd_event_page_set() The kfd_event_page_set()…

PriorityP344high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.14%
3.6th percentile
In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Fix out-of-bounds write in kfd_event_page_set() The kfd_event_page_set() function writes KFD_SIGNAL_EVENT_LIMIT * 8 bytes via memset without checking the buffer size parameter. This allows unprivileged userspace to trigger an out-of bounds kernel memory write by passing a small buffer, leading to potential privilege escalation.

Affected

42 ranges· showing 25
VendorProductVersion rangeFixed in
linuxlinux
linuxlinux>= 0fc8011f89feb8b2c3008583b777d097e1974660 < 3e04bc310d80b46eaf481f1fefcbcb37a187412d3e04bc310d80b46eaf481f1fefcbcb37a187412d
linuxlinux>= 0fc8011f89feb8b2c3008583b777d097e1974660 < de8d7a25cd2eb5875b1d8d4fbc7fe4b4138b781fde8d7a25cd2eb5875b1d8d4fbc7fe4b4138b781f
linuxlinux>= 0fc8011f89feb8b2c3008583b777d097e1974660 < b4034442cb090e4a980bdcc1540948606cbc951bb4034442cb090e4a980bdcc1540948606cbc951b
linuxlinux>= 0fc8011f89feb8b2c3008583b777d097e1974660 < 4857c37c7ba9aa38b9a4c694e8bd8d0091c879404857c37c7ba9aa38b9a4c694e8bd8d0091c87940
linuxlinux>= 0fc8011f89feb8b2c3008583b777d097e1974660 < 75fb57efdd7863fffbc39db23e9cad7aafda26ed75fb57efdd7863fffbc39db23e9cad7aafda26ed
linuxlinux>= 0fc8011f89feb8b2c3008583b777d097e1974660 < bfcd6b53e1f4feb182952f4ff9a137c36ceaf20bbfcd6b53e1f4feb182952f4ff9a137c36ceaf20b
linuxlinux>= 0fc8011f89feb8b2c3008583b777d097e1974660 < 4e72f419e4ed44cb3b60506752d8688c20a60a9b4e72f419e4ed44cb3b60506752d8688c20a60a9b
linuxlinux>= 0fc8011f89feb8b2c3008583b777d097e1974660 < 8a70a26c9f34baea6c3199a9862ddaff4554a96d8a70a26c9f34baea6c3199a9862ddaff4554a96d
linuxlinux_kernel>= 4.17 < 5.10.2525.10.252
linuxlinux_kernel>= 5.11 < 5.15.2025.15.202
linuxlinux_kernel>= 5.16 < 6.1.1656.1.165
linuxlinux_kernel>= 6.13 < 6.18.166.18.16
linuxlinux_kernel>= 6.19 < 6.19.66.19.6
linuxlinux_kernel>= 6.2 < 6.6.1286.6.128
linuxlinux_kernel>= 6.7 < 6.12.756.12.75
ubuntulinux
ubuntulinux-aws
ubuntulinux-aws-6.8
ubuntulinux-aws-fips
ubuntulinux-azure-fips
ubuntulinux-fips
ubuntulinux-gcp
ubuntulinux-gcp-6.8
ubuntulinux-gcp-fips

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_ubuntu8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.