U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

CVE-2026-43406 Detail

Description

In the Linux kernel, the following vulnerability has been resolved: libceph: prevent potential out-of-bounds reads in process_message_header() If the message frame is (maliciously) corrupted in a way that the length of the control segment ends up being less than the size of the message header or a different frame is made to look like a message frame, out-of-bounds reads may ensue in process_message_header(). Perform an explicit bounds check before decoding the message header.


Metrics

NVD enrichment efforts reference publicly available information to associate vector strings. CVSS information contributed by other sources is also displayed.
CVSS 4.0 Severity and Vector Strings:

NIST CVSS score
NIST: NVD
N/A
NVD assessment not yet provided.

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about this page to [email protected].

URL Source(s) Tag(s)
https://git.kernel.org/stable/c/035867ae6f18df0aeedb2a57a5b74091bd4e3fe8 kernel.org
https://git.kernel.org/stable/c/50156622eb0888e62541d715a98584480a1bc7cb kernel.org
https://git.kernel.org/stable/c/69fb5d91bba44ecf7eb80530b85fa4fb028921d5 kernel.org
https://git.kernel.org/stable/c/69fe5af33fa3806f398d21c081d73c66e5523bc2 kernel.org
https://git.kernel.org/stable/c/75582aaa580c11aed4c7731cad6b068b700e7efb kernel.org
https://git.kernel.org/stable/c/76ccf21a12c5f6d6790bc32c7da82446d877b2f4 kernel.org
https://git.kernel.org/stable/c/dbd857a9e1e33ea71eaf3e211877027e533770d1 kernel.org

Weakness Enumeration

CWE-ID CWE Name Source

Change History

1 change records found show changes

Quick Info

CVE Dictionary Entry:
CVE-2026-43406
NVD Published Date:
05/08/2026
NVD Last Modified:
05/08/2026
Source:
kernel.org