PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-43449 Linux CVE debrief

CVE-2026-43449 is a Linux kernel NVMe PCI driver vulnerability that can cause a slab-out-of-bounds read in nvme_dbbuf_set. NVD assigns it CVSS 7.1 HIGH and classifies the weakness as CWE-125. The kernel fix notes state that dev->online_queues is a count incremented in nvme_init_queue, so valid indices are 0 through dev->online_queues - 1, and the loop condition was corrected to stay within that range while excluding index 0 because it is the admin queue.

Vendor
Linux
Product
Unknown
CVSS
HIGH 7.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-08
Original CVE updated
2026-05-21
Advisory published
2026-05-08
Advisory updated
2026-05-21

Who should care

Linux kernel maintainers, distribution security teams, and operators running systems with NVMe PCI storage should prioritize this issue, especially where kernel updates are managed conservatively and NVMe reset paths may be exercised.

Technical summary

The issue is in drivers/nvme/host/pci.c and is triggered during nvme_dbbuf_set / nvme_dbbuf_free handling. The provided KASAN report shows an out-of-bounds read of size 2 in nvme_dbbuf_free, reached from nvme_dbbuf_set during nvme_reset_work. According to the fix note, the bug came from iterating beyond the valid queue index range because dev->online_queues is a count, not a highest index. NVD lists affected Linux kernel ranges across multiple release lines, including versions before 4.15, 4.20, 5.5, 5.10.253, 5.15.203, 6.1.167, 6.6.130, 6.12.78, 6.18.19, and 6.19.9, plus certain 5.10 and 7.0 release candidates.

Defensive priority

High. The flaw is memory-safety related, reachable in kernel space, and rated HIGH by NVD. Even though the CVSS vector is local and requires low privileges, kernel memory corruption or disclosure issues warrant prompt patching on affected systems.

Recommended defensive actions

  • Apply the vendor kernel patch from the linked stable Git references.
  • Upgrade to a Linux kernel release that includes the fix for your branch.
  • Prioritize patching systems that use NVMe PCI devices or that frequently exercise NVMe reset paths.
  • Verify affected kernel versions against the NVD CPE ranges before scheduling maintenance.
  • Monitor kernel advisories and downstream distribution errata for backported fixes.

Evidence notes

All claims are grounded in the supplied NVD record and the embedded kernel fix note. The KASAN report in the description shows the fault in nvme_dbbuf_set while handling nvme_reset_work. NVD lists the CVSS vector as CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H and the weakness as CWE-125. Reference links in the corpus point to kernel.org stable patch entries, supporting that this is a fixed kernel driver bug rather than an unverified report.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-43449 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-43449

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-43449 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-43449

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/2b9d605c3f0d3262142f196249cd3bd58c857c71

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/328c551f0cc81ee776b186b86cc6e5253bb6fda7

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/50bad78f03a02d3c0f228edf9912b494d3e7acb9

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/78279d2d74c58a0ed64e43cf601a02649771182e

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/83e6edd6358326c9c2de31a54bb4a1ec50703f1f

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/86183d550559e45e07059bbdf17331fea469e38c

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/b4e78f1427c7d6859229ae9616df54e1fc05a516

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.