CVE-2026-43463: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: rxrpc, afs: Fix missing error pointer check after rxrpc_kernel_lookup_peer() rxrpc_kernel_lookup_peer() can also return error pointers in addition to NULL, so just checking for NULL is not sufficient. Fix this by: (1) Changing rxrpc_kernel_lookup_peer() to return -ENOMEM rather than NULL on allocation failure. (2) Making the callers in afs use IS_ERR() and PTR_ERR() to pass on the error code returned.

Affected products

  • Linux Linux Kernel: from 6.7.3, before 6.8 (fixed in 6.8); from 6.8, before 6.18.19 (fixed in 6.18.19); from 6.19, before 6.19.9 (fixed in 6.19.9); version 7.0 only

Published 2026-05-08. Last modified 2026-06-17.