Answer in brief
CVE-2026-43248 records a Unknown severity vulnerability in vhost: move vdpa group bound check to vhost_vdpa. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=bda324fd037a6b0d44da5699574ce741ca161bc4 <ddb57354634b6ba851b79da45f1de42c646f27d0 || >=bda324fd037a6b0d44da5699574ce741ca161bc4 <7441d35d14d9a3d66d925d90cb73c75394e6d454 || >=bda324fd037a6b0d44da5699574ce741ca161bc4 <406db68f9cb976a8ddfafd631197264f2307e9c9 || >=bda324fd037a6b0d44da5699574ce741ca161bc4 <cd025c1e876b4e262e71398236a1550486a73ede | ddb57354634b6ba851b79da45f1de42c646f27d0, 7441d35d14d9a3d66d925d90cb73c75394e6d454, 406db68f9cb976a8ddfafd631197264f2307e9c9, cd025c1e876b4e262e71398236a1550486a73ede |
| Linux/Linuxgeneric | 5.19 | Not reported |
Published upstream
May 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: vhost: move vdpa group bound check to vhost_vdpa Remove duplication by consolidating these here. This reduces the posibility of a parent driver missing them. While we're at it, fix a bug in vdpa_sim where a valid ASID can be assigned to a group equal to ngroups, causing an out of bound write.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2026-43248 records a Unknown severity vulnerability in vhost: move vdpa group bound check to vhost_vdpa. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=bda324fd037a6b0d44da5699574ce741ca161bc4 <ddb57354634b6ba851b79da45f1de42c646f27d0 || >=bda324fd037a6b0d44da5699574ce741ca161bc4 <7441d35d14d9a3d66d925d90cb73c75394e6d454 || >=bda324fd037a6b0d44da5699574ce741ca161bc4 <406db68f9cb976a8ddfafd631197264f2307e9c9 || >=bda324fd037a6b0d44da5699574ce741ca161bc4 <cd025c1e876b4e262e71398236a1550486a73ede | ddb57354634b6ba851b79da45f1de42c646f27d0, 7441d35d14d9a3d66d925d90cb73c75394e6d454, 406db68f9cb976a8ddfafd631197264f2307e9c9, cd025c1e876b4e262e71398236a1550486a73ede |
| Linux/Linuxgeneric | 5.19 | Not reported |
Published upstream
May 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: vhost: move vdpa group bound check to vhost_vdpa Remove duplication by consolidating these here. This reduces the posibility of a parent driver missing them. While we're at it, fix a bug in vdpa_sim where a valid ASID can be assigned to a group equal to ngroups, causing an out of bound write.
Quoted source text, attributed separately from HOL analysis.