CVE-2026-43058Patch(linux / linux_kernel)

MEDIUMCVSS 5.5 · MEDIUM

Exploitation ongoing with high activity in latest observed window (5 mentions)

Immediate actions

  • Patch linux linux_kernel systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

In the Linux kernel, the following vulnerability has been resolved: media: vidtv: fix pass-by-value structs causing MSAN warnings vidtv_ts_null_write_into() and vidtv_ts_pcr_write_into() take their argument structs by value, causing MSAN to report uninit-value warnings. While only vidtv_ts_null_write_into() has triggered a report so far, both functions share the same issue. Fix by passing both structs by const pointer instead, avoiding the stack copy of the struct along with its MSAN shadow and origin metadata. The functions do not modify the structs, which is enforced by the const qualifier.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-476

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • linux_kernel

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 5 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 5 total mentions across 1 day

Affected systems

Vendors
Products
linux_kernel

Deep dive

Activity timeline5 mentions / 1d
01345Mentions · 2026-05-02: 5Active Exploitation · 2026-05-02: 1Patch / Workaround · 2026-05-02: 1Technical Details · 2026-05-02: 105-02
Signal classification4 categories
Patch
240.0%
Active Exploitation
120.0%
Disclosure
120.0%
General
120.0%
Referenced assets6 URLs
Full discourse5 posts
  • VulDB 🛡@vuldb
    Active Exploitation

    A lot of offensive activities were identified targeting Linux Kernel (CVE-2026-43058) https://vuldb.com/vuln/360816/cti

    Post summary

    The statement indicates that CVE-2026-43058 is being actively exploited, though no PoC, exploit code, patch, or detailed technical information is provided.

    0000055
    2.1K followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    There is a new vulnerability with elevated criticality in Linux Kernel (CVE-2026-43058) https://vuldb.com/vuln/360816

    Post summary

    A new Linux Kernel vulnerability (CVE-2026-43058) is announced with elevated criticality, but no technical, exploit, or mitigation details are provided.

    0000059
    2.1K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-43058 Memory Sanitizer Warnings Resolution in Linux Kernel vidtv Pass-b... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-43058 Customizable Vulnerability Alerts: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=4

    Post summary

    The tweet merely lists CVE-2026-43058 and links to a Vulmon page, providing no further technical or exploit information.

    0000067
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Patch

    🚨*CVE* CVE-2026-43058 In the Linux kernel, the following vulnerability has been resolved: media: vidtv: fix pass-by-value structs causing MSAN warnings vidtv_ts_null_write_into() and vid… https://www.cve.org/CVERecord?id=CVE-2026-43058 ----- Traducción: CVE-2026-43058 En … http://infoflow.cloud`

    Post summary

    CVE‑2026‑43058, a media driver flaw in the Linux kernel involving pass‑by‑value struct handling, has been fixed with a kernel patch that removes the MSAN warnings.

    0000028
    75 followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-43058 In the Linux kernel, the following vulnerability has been resolved: media: vidtv: fix pass-by-value structs causing MSAN warnings vidtv_ts_null_write_into() and vid… https://www.cve.org/CVERecord?id=CVE-2026-43058

    Post summary

    The post simply notes that CVE‑2026‑43058 has been fixed in the Linux kernel, with no additional exploitation or patch details.

    00000188
    57.4K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
OSlinuxlinux_kernel---

Explore more