CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-43494

criticalcovered by 6 sourcesfirst seen 2026-06-23
View CSAF Summary B&R is aware of publicly reported vulnerabilities affecting the Linux kernel versions shipped with the products listed as affected in the advisory. Successful local exploitation of these vulnerabilities could allow an attacker to escalate privileges on the affected system. Public proof-of-concept exploits are available for the vulnerabilities described herein. At the time of publication of this advisory, B&R had no evidence of active exploitation targeting B&R products. The following versions of Impact of Linux Kernel vulnerabilities on B&R products are affected: Linux for B&R <=12 APROL <APROL-AutoYaST-DVD- V4.4-010.10.260602 X20EDS410 /all CVSS Vendor Equipment Vulnerabilities v3 7.8 B&R Industrial Automation GmbH Impact of Linux Kernel vulnerabilities on B&R products Incorrect Resource Transfer Between Spheres, Write-what-where Condition, Improper Privilege Management, Out-of-bounds Write, Multiple Releases of Same Resource or Handle Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: Switzerland Vulnerabilities Expand All + CVE-2026-31431 In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different mappings. Get rid of all the complexity added for in-place operation and just copy the AD directly. View CVE Details Affected Products Impact of Linux Kernel vulnerabilities on B&R products Vendor: B&R Industrial Automation GmbH Product Version: B&R Industrial Automation GmbH Linux for B&R <=12, B&R Industrial Automation GmbH APROL <APROL-AutoYaST-DVD- V4.4-010.10.260602, B&R Industrial Automation GmbH X20EDS410 /all Product Status: fixed, known_affected Remediations Vendor fix For affected products, softw

CSIRTS triage

vendor: B&R Industrial Automation GmbHproduct: Linux for B&RPrivilege escalationaffected: <=12 APROL <APROL-AutoYaST-DVD- V4.4-010.10.260602 X20EDS410 /all
What
Local exploitation of vulnerabilities in the Linux kernel could allow privilege escalation.
Who is affected
Deployments of B&R products using the affected Linux kernel versions.
Urgency
Remediation is urgent due to the availability of public proof-of-concept exploits and the critical severity of the vulnerabilities.
Action
Update to the latest version of the Linux kernel as recommended by B&R.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-43494

Get an email if CVE-2026-43494 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (6)

External references

NVD record for CVE-2026-43494

CVE.org record

Embed the live status

CVE-2026-43494 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-43494 status](https://www.csirts.com/badge/CVE-2026-43494)](https://www.csirts.com/cve/CVE-2026-43494)