PT-2026-39094 · Linux · Linux Kernel
Published
2026-05-08
·
Updated
2026-05-15
·
CVE-2026-43433
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A Time-of-Check to Time-of-Use (TOCTOU) issue exists in the
rust binder component. When a transaction is sent, the offsets array is copied into the target process's virtual memory area (VMA) and subsequently read back. If a target process can write to its own read-only VMA, it could modify the offset before the kernel reads it. This could lead to the kernel misinterpreting the sender's intent and potentially allow the receiver to escalate privileges into the sender.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel