CVE-2026-43499
Five independent official sources cover this CVE — the upstream Linux kernel CVE announcement, Red Hat, Ubuntu, Debian and SUSE — each on its own host, one row per source. Scores are CVSS v3.1 7.8 High and CVSS v4.0 8.5 High; the flaw was introduced in Linux 2.6.39 and published upstream on 2026-05-21. Exploitation in the wild is unconfirmed: none of the five sources states an in-the-wild status.
These are upstream kernel.org releases, not distribution packages. Distributors backport the fix, so never judge a vendor kernel safe or unsafe by its upstream version string alone.
| Source | Severity / CVSS | Requirements | Affected / fixed | Dates |
|---|---|---|---|---|
| lore.kernel.org | — | — | introduced in 2.6.39; fixed in 6.6.140, 6.12.86, 6.18.27, 7.0.4, 7.1-rc1 | 2026-05-21 |
| access.redhat.com | CVSS v3.1 Base Score: 7.8, Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H | Attack Vector: Local, Attack Complexity: Low, Privileges Required: Low, User Interaction: None | — | — |
| ubuntu.com | Base score 8.5 · High, Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N, CVSS version: CVSS version: | Attack Vector: Local, Attack Complexity: Low, Attack Requirements: None, Privileges Required: Low, User Interaction: Non… | linux: introduced by 8161239, fixed by 3bfdc63 | Publication date 21 May 2026, Last updated 31 August 2026 |
| security-tracker.debian.org | — | — | bullseye: 5.10.262-1, 6.1.176-1~deb11u1; bookworm: 6.1.176-1; trixie: 6.12.86-1; (unstable): 7.0.4-1 | — |
| suse.com | Base Score: 7.8 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) / Base Score: 8.5 (CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N… | Attack Vector: Local, Attack Complexity: Low, Privileges Required: Low, User Interaction: None / Attack Requirements: No… | kernel-default >= 6.4.0-47.1, kernel-default-base >= 6.4.0-47.1.21.24, kernel-default >= 5.14.21-150400.24.222.1, kernel-default >= 5.14.21-150500.55.169.1, ker… | published 2026-06-05T16:14:08Z, published 2026-06-05T16:12:36Z, published 2026-0… |
Data: 5 result rows, one per official source (Linux kernel CVE announce, Red Hat, Ubuntu, Debian, SUSE), each from its own host and URL; fields cover description, CVSS scores, attack requirements, impacts, affected/fixed versions and dates. CVSS scores are vendor-published base scores. SUSE's long per-package fixed-version list and repeated publish timestamps are truncated for space. Exploitation-in-the-wild status: unconfirmed (not stated by any source). Collected 2026.