CVE-2026-43241
In the Linux kernel, the following vulnerability has been resolved: ntb: ntb_hw_switchtec: Fix array-index-out-of-bounds access Number of MW LUTs depends on NTB configuration and can be set to MAX_MWS, This patch protects against invalid index out of…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.13%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
In the Linux kernel, the following vulnerability has been resolved: ntb: ntb_hw_switchtec: Fix array-index-out-of-bounds access Number of MW LUTs depends on NTB configuration and can be set to MAX_MWS, This patch protects against invalid index out of bounds access to mw_sizes When invalid access print message to user that configuration is not valid.
- CVSS 3.1
- 7.1 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
- EPSS
- 0.13% probability · 3th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-125
- Affected
- linux/linux kernel
- Source
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
References
- https://git.kernel.org/stable/c/0e930420945106151c6eb3d7837b4e6154e9b144Patch
- https://git.kernel.org/stable/c/2346856b74823a2a78109002e479a3d02526a9cePatch
- https://git.kernel.org/stable/c/348e1ac9ad983ed7e62de14e1daf47f1695a4ce9Patch
- https://git.kernel.org/stable/c/47ce292dd45dc689747c40603222691638919189Patch
- https://git.kernel.org/stable/c/740945de896021b9a859e71f38f6aea72a6393cfPatch
- https://git.kernel.org/stable/c/85c9daa1f8319bbb3dfee71dc6a2f969cd3b4c92Patch
- https://git.kernel.org/stable/c/c8ba7ad2cc1c7b90570aa347b8ebbe279f1efacePatch
- https://git.kernel.org/stable/c/ee02c4f980c91820845dd8e469ec7dc670ab6d9dPatch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.