PT-2026-38948 · Linux · Linux Kernel
Published
2026-05-08
·
Updated
2026-05-15
·
CVE-2026-43306
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A type mismatch occurs in the Linux kernel when
CONFIG CFI (Control Flow Integrity, a security mechanism that ensures indirect function calls target the correct function type) is enabled. This happens because the destructor kfunc type does not match the target function bpf crypto ctx release(), which can lead to a CFI failure and a system crash (Oops).Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel