Answer in brief
CVE-2026-43433 records a Unknown severity vulnerability in rust_binder: avoid reading the written value in offsets array. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=eafedbc7c050c44744fbdf80bdf3315e860b7513 <e19afb53f7723b3bd22224f2b0c7dcfa70bb973f || >=eafedbc7c050c44744fbdf80bdf3315e860b7513 <3672141c93b7a0c0132bf5d5021a4b7f1d663aaa || >=eafedbc7c050c44744fbdf80bdf3315e860b7513 <4cb9e13fec0de7c942f5f927469beb8e48ddd20f | e19afb53f7723b3bd22224f2b0c7dcfa70bb973f, 3672141c93b7a0c0132bf5d5021a4b7f1d663aaa, 4cb9e13fec0de7c942f5f927469beb8e48ddd20f |
| Linux/Linuxgeneric | 6.18 | Not reported |
Published upstream
May 8, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: rust_binder: avoid reading the written value in offsets array When sending a transaction, its offsets array is first copied into the target proc's vma, and then the values are read back from there. This is normally fine because the vma is a read-only mapping, so the target process cannot change the value under us. However, if the target process somehow gains the ability to write to its own vma, it could change the offset before it's read back, causing the kernel to misinterpret what the sender meant. If the sender happens to send a payload with a specific shape, this could in the worst case lead to the receiver being able to privilege escalate into the sender. The intent is that gaining the ability to change the read-only vma of your own process should not be exploitable, so remove this TOCTOU read even though it's unexploitable without another Binder bug.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2026-43433 records a Unknown severity vulnerability in rust_binder: avoid reading the written value in offsets array. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=eafedbc7c050c44744fbdf80bdf3315e860b7513 <e19afb53f7723b3bd22224f2b0c7dcfa70bb973f || >=eafedbc7c050c44744fbdf80bdf3315e860b7513 <3672141c93b7a0c0132bf5d5021a4b7f1d663aaa || >=eafedbc7c050c44744fbdf80bdf3315e860b7513 <4cb9e13fec0de7c942f5f927469beb8e48ddd20f | e19afb53f7723b3bd22224f2b0c7dcfa70bb973f, 3672141c93b7a0c0132bf5d5021a4b7f1d663aaa, 4cb9e13fec0de7c942f5f927469beb8e48ddd20f |
| Linux/Linuxgeneric | 6.18 | Not reported |
Published upstream
May 8, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: rust_binder: avoid reading the written value in offsets array When sending a transaction, its offsets array is first copied into the target proc's vma, and then the values are read back from there. This is normally fine because the vma is a read-only mapping, so the target process cannot change the value under us. However, if the target process somehow gains the ability to write to its own vma, it could change the offset before it's read back, causing the kernel to misinterpret what the sender meant. If the sender happens to send a payload with a specific shape, this could in the worst case lead to the receiver being able to privilege escalate into the sender. The intent is that gaining the ability to change the read-only vma of your own process should not be exploitable, so remove this TOCTOU read even though it's unexploitable without another Binder bug.
Quoted source text, attributed separately from HOL analysis.