CVE-2026-43406
In the Linux kernel, the following vulnerability has been resolved: ksmbd: ipc: fix use-after-free in ipc_msg_send_request ipc_msg_send_request() waits for a generic netlink reply using an ipc_msg_table_entry on the stack. In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free of share_conf in compound request smb2_get_ksmbd_tcon() reuses work->tcon in compound requests without validating tcon->t_state. In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_h323: check for zero length in DecodeQ931() In DecodeQ931(), the UserUserIE code path reads a 16-bit length from the packet, then decrements it by 1 to skip the protocol discriminator byte before passing it to DecodeH323_UserInformation(). In the Linux kernel, the following vulnerability has been resolved: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache The NFSv4.0 replay cache uses a fixed 112-byte inline buffer (rp_ibuf. In the Linux kernel, the following vulnerability has been resolved: media: dvb-net: fix OOB access in ULE extension header tables The ule_mandatory_ext_handlers. It was discovered that the Linux kernel algif_aead module did not properly handle in-place cryptographic operations. This flaw is known as Copy Fail. A local attacker could use this to escalate privileges, or possibly escape a container.)(CVE-2026-31431) In the Linux kernel, the following vulnerability has been resolved: ksmbd: replace hardcoded hdr2_len with offsetof() in smb2_calc_max_out_buf_len() After this commit (e2b76ab8b5c9 'ksmbd: add support for read compound'), response buffer management was changed to use dynamic iov array. In the Linux kernel, the following vulnerability has been resolved: usbip: validate number_of_packets in usbip_pack_ret_submit() When a USB/IP client receives a RET_SUBMIT response, usbip_pack_ret_submit() unconditionally overwrites urb->number_of_packets from the network PDU. This value is subsequently used as the loop boun
CSIRTS triage
- What
- Linux kernel contains use-after-free and buffer overflow vulnerabilities in ksmbd IPC, netfilter, and NFSv4.0 subsystems.
- Who is affected
- Linux systems running affected kernel versions, particularly those with ksmbd, netfilter, and NFSv4 enabled.
- Urgency
- Critical; actively exploited vulnerabilities affecting core kernel subsystems.
- Action
- Apply Linux kernel security updates from your distribution immediately; apply live patches if available.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2026-43406
Get an email if CVE-2026-43406 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Low exploitation risk0.50% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 41% of all EPSS-scored CVEs.
Advisory coverage (17)
- unknownexploitedLSN-0121-1: Kernel Live Patch Security Noticeubuntu · 2026-08-27
- highUSN-8619-1: Linux kernel (HWE) vulnerabilitiesubuntu · 2026-07-28
- unknownUSN-8547-2: Linux kernel (Azure FIPS) vulnerabilitiesubuntu · 2026-07-28
- highUSN-8609-1: Linux kernel (Azure CVM) vulnerabilitiesubuntu · 2026-07-24
- highUSN-8607-1: Linux kernel (Azure CVM) vulnerabilitiesubuntu · 2026-07-24
- highUSN-8606-1: Linux kernel (Azure) vulnerabilitiesubuntu · 2026-07-24
- unknownUSN-8605-1: Linux kernel (Azure CVM) vulnerabilitiesubuntu · 2026-07-24
- unknownUSN-8604-1: Linux kernel (Azure) vulnerabilitiesubuntu · 2026-07-24
- unknownUSN-8490-2: Linux kernel (Real-time) vulnerabilitiesubuntu · 2026-07-17
- unknownUSN-8490-1: Linux kernel vulnerabilitiesubuntu · 2026-07-17
- unknownUSN-8547-1: Linux kernel vulnerabilitiesubuntu · 2026-07-15
- unknownUSN-8546-1: Linux kernel (Raspberry Pi) vulnerabilitiesubuntu · 2026-07-15
- unknownUSN-8545-1: Linux kernel (HWE) vulnerabilitiesubuntu · 2026-07-15
- unknownexploitedUSN-8528-1: Linux kernel (Xilinx ZynqMP) vulnerabilitiesubuntu · 2026-07-10
- unknownUSN-8527-1: Linux kernel (Raspberry Pi) vulnerabilitiesubuntu · 2026-07-10
- unknownUSN-8492-5: Linux kernel (FIPS) vulnerabilitiesubuntu · 2026-07-10
- unknownUSN-8492-4: Linux kernel (Raspberry Pi) vulnerabilitiesubuntu · 2026-07-09
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-43406)