CVE-2026-43078: crypto: af_alg - Fix page reassignment overflow in af_alg_pull_tsgl
Published May 6, 2026
·Updated
In the Linux kernel, the following vulnerability has been resolved:
Affected Software
17 affected componentsFixes available
Linux Linux kernel
Linux Linux kernel>=4.14.1<5.10.254
Linux Linux kernel>=5.11<5.15.204
Linux Linux kernel>=5.16<6.1.170
Linux Linux kernel>=6.2<6.6.137
Linux Linux kernel>=6.7<6.12.85
Linux Linux kernel>=6.13<6.18.24
Linux Linux kernel>=6.19<6.19.14
Linux Linux kernel=4.14
Linux Linux kernel=7.0-rc1
Linux Linux kernel=7.0-rc2
Linux Linux kernel=7.0-rc3
Linux Linux kernel=7.0-rc4
Linux Linux kernel=7.0-rc5
Linux Linux kernel=7.0-rc6
Linux Linux kernel=7.0-rc7
debian/linux<=5.10.223-1
5.10.257-16.1.170-36.1.174-16.12.86-16.12.94-17.0.12-27.0.13-1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.257-1Fixed in 6.1.170-3Fixed in 6.1.174-1Fixed in 6.12.86-1Fixed in 6.12.94-1Fixed in 7.0.12-2Fixed in 7.0.13-1
Event History
May 6, 2026
CVE Published
via MITRE·07:40 AM
Data Sourced
via MITRE·07:40 AM
DescriptionSeverity
Data Sourced
via NVD·10:16 AM
RemedyDescriptionSeverityWeaknessAffected Software
May 19, 2026
Data Sourced
via Launchpad·11:40 PM
Description
Jun 18, 2026
Data Sourced
via Ubuntu·10:22 PM
RemedyDescriptionSeverityAffected Software
Jun 21, 2026
Data Sourced
via Debian·10:27 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-43078?
The severity of CVE-2026-43078 is rated as high with a score of 7.8.
2
How do I fix CVE-2026-43078?
The fix for CVE-2026-43078 is available through a patch that should be applied to the Linux kernel.
3
What software is affected by CVE-2026-43078?
CVE-2026-43078 affects the Linux kernel, including distributions based on Debian.
4
When was CVE-2026-43078 published?
CVE-2026-43078 was published on May 6, 2026.
5
What does CVE-2026-43078 exploit?
CVE-2026-43078 exploits a page reassignment overflow in the af_alg_pull_tsgl function in the Linux kernel.