vhost: move vdpa group bound check to vhost_vdpa
Summary
| CVE | CVE-2026-43248 |
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-05-06 12:16:45 UTC |
| Updated | 2026-05-06 13:07:51 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved:
vhost: move vdpa group bound check to vhost_vdpa
Remove duplication by consolidating these here. This reduces the
posibility of a parent driver missing them.
While we're at it, fix a bug in vdpa_sim where a valid ASID can be
assigned to a group equal to ngroups, causing an out of bound write. |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|
| CNA |
Linux |
Linux |
affected bda324fd037a6b0d44da5699574ce741ca161bc4 ddb57354634b6ba851b79da45f1de42c646f27d0 git |
Not specified |
| CNA |
Linux |
Linux |
affected bda324fd037a6b0d44da5699574ce741ca161bc4 7441d35d14d9a3d66d925d90cb73c75394e6d454 git |
Not specified |
| CNA |
Linux |
Linux |
affected bda324fd037a6b0d44da5699574ce741ca161bc4 406db68f9cb976a8ddfafd631197264f2307e9c9 git |
Not specified |
| CNA |
Linux |
Linux |
affected bda324fd037a6b0d44da5699574ce741ca161bc4 cd025c1e876b4e262e71398236a1550486a73ede git |
Not specified |
| CNA |
Linux |
Linux |
affected 5.19 |
Not specified |
| CNA |
Linux |
Linux |
unaffected 5.19 semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.12.75 6.12.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.18.16 6.18.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.19.6 6.19.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.0 * original_commit_for_fix |
Not specified |
References
| Reference | Source | Link | Tags |
|---|
| git.kernel.org/stable/c/cd025c1e876b4e262e71398236a1550486a73ede |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/406db68f9cb976a8ddfafd631197264f2307e9c9 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/7441d35d14d9a3d66d925d90cb73c75394e6d454 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/ddb57354634b6ba851b79da45f1de42c646f27d0 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.