Security Advisory

CVE-2026-43248

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-05-06 11:28:39
Last updated 2026-05-11 22:20:52
Assigner Linux
CVSS score 7.8
State PUBLISHED

Description

In the Linux kernel, the following vulnerability has been resolved: vhost: move vdpa group bound check to vhost_vdpa Remove duplication by consolidating these here. This reduces the posibility of a parent driver missing them. While we're at it, fix a bug in vdpa_sim where a valid ASID can be assigned to a group equal to ngroups, causing an out of bound write.