CVE-2026-43208: Linux Kernel

Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: net: do not pass flow_id to set_rps_cpu() Blamed commit made the assumption that the RPS table for each receive queue would have the same size, and that it would not change. Compute flow_id in set_rps_cpu(), do not assume we can use the value computed by get_rps_cpu(). Otherwise we risk out-of-bound access and/or crashes.

Affected products

  • Linux Linux Kernel: from 6.18, before 6.18.16 (fixed in 6.18.16); from 6.19, before 6.19.6 (fixed in 6.19.6); version 7.0 only

Published 2026-05-06. Last modified 2026-06-17.