CVE-2026-43043 Details
Description
In the Linux kernel, the following vulnerability has been resolved: crypto: af-alg - fix NULL pointer dereference in scatterwalk The AF_ALG interface fails to unmark the end of a Scatter/Gather List (SGL) when chaining a new af_alg_tsgl structure. If a sendmsg() fills an SGL exactly to MAX_SGL_ENTS, the last entry is marked as the end. A subsequent sendmsg() allocates a new SGL and chains it, but fails to clear the end marker on the previous SGL's last data entry. This causes the crypto scatterwalk to hit a premature end, returning NULL on sg_next() and leading to a kernel panic during dereference. Fix this by explicitly unmarking the end of the previous SGL when performing sg_chain() in af_alg_alloc_tsgl().
A vulnerability in the Linux kernel's AF_ALG interface can lead to a NULL pointer dereference and a subsequent kernel panic. This issue arises because the interface fails to properly manage the end marker of a Scatter/Gather List (SGL) when chaining new structures. Specifically, if a sendmsg() operation fills an SGL to its maximum capacity, the last entry is marked as the end. However, when a subsequent sendmsg() allocates a new SGL and chains it without clearing the end marker on the previous SGL, the crypto scatterwalk encounters a premature end. This mismanagement causes a NULL return on sg_next(), which, when dereferenced, leads to a kernel panic.
The vulnerability has been fixed in the Linux kernel. Users should upgrade to the latest version.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/00cbdec17c15d024a1c5002c7365df7624a18a75 | kernel.org | Patch |
| https://git.kernel.org/stable/c/44eafa39363e8d5dfda6a8c6eb6b45458ed4b948 | kernel.org | Patch |
| https://git.kernel.org/stable/c/4b03ab0a587ec57eb7ddb5c115d84a42896f60f7 | kernel.org | Patch |
| https://git.kernel.org/stable/c/62397b493e14107ae82d8b80938f293d95425bcb | kernel.org | Patch |
| https://git.kernel.org/stable/c/7195350fb78538c25cd790d703f8f2c73ee0d395 | kernel.org | Patch |
| https://git.kernel.org/stable/c/7cdf2c6381b21ab5ccf8116750d5582fcd6c0f49 | kernel.org | Patch |
| https://git.kernel.org/stable/c/f48d3dd99199180cf37d6253550c55e86372309a | kernel.org | Patch |
| https://git.kernel.org/stable/c/f9acceae7b004956851fd4268edf9f518a9bce04 | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-476 | NULL Pointer Dereference | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 2.6.38, < 5.10.253 >= 5.11, < 5.15.203 >= 5.16, < 6.1.168 >= 6.2, < 6.6.134 >= 6.7, < 6.12.81 >= 6.13, < 6.18.22 >= 6.19, < 6.19.12 7.0 rc1 7.0 rc2 7.0 rc3 7.0 rc4 7.0 rc5 7.0 rc6 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | kernel.org |
| May 8, 2026 | Initial Analysis | [email protected] |
| May 1, 2026 | New CVE Received | kernel.org |