CVE-2026-43495Disclosure(linux / linux_kernel)

LOWCVSS 8.8 · HIGH

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Prioritize remediation for linux linux_kernel systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

In the Linux kernel, the following vulnerability has been resolved: net: wwan: t7xx: validate port_count against message length in t7xx_port_enum_msg_handler t7xx_port_enum_msg_handler() uses the modem-supplied port_count field as a loop bound over port_msg->data[] without checking that the message buffer contains sufficient data. A modem sending port_count=65535 in a 12-byte buffer triggers a slab-out-of-bounds read of up to 262140 bytes. Add a sizeof(*port_msg) check before accessing the port message header fields to guard against undersized messages. Add a struct_size() check after extracting port_count and before the loop. In t7xx_parse_host_rt_data(), guard the rt_feature header read with a remaining-buffer check before accessing data_len, validate feat_data_len against the actual remaining buffer to prevent OOB reads and signed integer overflow on offset. Pass msg_len from both call sites: skb->len at the DPMAIF path after skb_pull(), and the validated feat_data_len at the handshake path.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-125

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • linux_kernel

Threat summary

  • Active exploitation appears in 1 classified signals
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • General: 2 classified signals
  • Peaked 2d ago at 2 mentions (2026-05-21); latest day: 2
  • 6 total mentions across 3 days

Affected systems

Vendors
Products
linux_kernel

1 version affected across 1 product

Deep dive

Activity timeline6 mentions / 3d
01122Mentions · 2026-05-21: 2Mentions · 2026-05-22: 2Mentions · 2026-06-19: 2Active Exploitation · 2026-05-22: 1Technical Details · 2026-05-22: 1Technical Details · 2026-06-19: 205-2105-2206-19
Signal classification3 categories
Disclosure
350.0%
General
233.3%
Active Exploitation
116.7%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-05-212
General2
2026-05-222
Active Exploitation1Disclosure1
2026-06-192
Disclosure2
Full discourse6 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2026-43495: Linux kernel: Slab out-of-bounds read in MediaTek t7xx WWAN driver https://www.openwall.com/lists/oss-security/2026/06/18/1 "Requires control of the baseband modem processor (e.g., via OTA base station exploit or hardware attack). The t7xx family is used [...] in corporate laptops"

    Post summary

    A Linux kernel out‑of‑bounds read vulnerability (CVE-2026‑43495) in MediaTek t7xx WWAN drivers is disclosed; requires control of the baseband modem, but no PoC, exploit, or patch information is provided.

    010421.0K
    4.7K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-43495 In the Linux kernel, the following vulnerability has been... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-43495 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    A brief tweet referencing CVE-2026-43495 and linking to external vulnerability details, without providing substantive technical or exploitation information.

    0001063
    4.0K followersView on X
  • Can Artuc@canartuc
    Disclosure

    A slab out-of-bounds read in the Linux kernel MediaTek t7xx WWAN driver (CVE-2026-43495) lets a malicious modem payload read ~262 KB past the buffer, because t7xx_port_enum_msg_handler() trusts port_count. Affected from v5.18-rc1 to mainline. Do you trust your modem firmware?

    Post summary

    The passage discloses CVE‑2026‑43495, a slab out‑of‑bounds read in the MediaTek t7xx WWAN driver, detailing the affected code path and extent of the buffer read.

    0000037
    171 followersView on X
  • WindowsForum@windowsforum
    Disclosure

    🪟 Linux kernel OOB read in a MediaTek 5G modem driver… so the “secure” laptop is one malformed modem message away from kernel memory peek-a-boo. Edge devices are growing teeth—patch time. #Windows #Linux #Security #CVE #PatchNow https://windowsforum.com/threads/cve-2026-43495-linux-modem-driver-bug-kernel-oob-read-in-mediatek-t7xx.419279/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #OutOfBoundsRead https://t.co/pZVcC7BHVd

    Post summary

    The post announces a Linux kernel out‑of‑bounds read in a MediaTek 5G modem driver (CVE‑2026‑43495) and urges patching, but offers no PoC, exploit, or specific remediation details.

    0000054
    1.1K followersView on X
  • VulDB 🛡@vuldb
    Active Exploitation

    A lot of offensive activities were identified targeting Linux Kernel (CVE-2026-43495) https://vuldb.com/vuln/365011/cti

    Post summary

    The statement reports ongoing offensive activity targeting the Linux Kernel CVE‑2026‑43495, indicating real‑world exploitation but lacking details on PoC, tools, patches, or technical aspects.

    0000071
    2.2K followersView on X
  • VulDB 🛡@vuldb
    General

    There is a new vulnerability with elevated criticality in Linux Kernel (CVE-2026-43495) https://vuldb.com/vuln/365011

    Post summary

    The post announces a new Linux kernel vulnerability (CVE-2026-43495) and links to a VulDB entry, but offers no further technical or exploitation details.

    0000081
    2.2K followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
OSlinuxlinux_kernel---
OSlinuxlinux_kernel7.1--
OSlinuxlinux_kernel7.1--

Explore more