CVE-2026-43321: bpf: Properly mark live registers for indirect jumps
Published May 8, 2026
·Updated
bpf: Properly mark live registers for indirect jumps
Affected Software
10 affected componentsFixes available
Linux Linux kernel
Microsoft azl3 kernel 6.6.137.1-2
Linux Linux kernel>=6.19<6.19.6
Linux Linux kernel=7.0-rc1
Linux Linux kernel=7.0-rc2
Linux Linux kernel=7.0-rc3
Linux Linux kernel=7.0-rc4
Linux Linux kernel=7.0-rc5
Linux Linux kernel=7.0-rc6
Linux Linux kernel=7.0-rc7
Event History
May 8, 2026
CVE Published
via MITRE·01:26 PM
Data Sourced
via MITRE·01:26 PM
DescriptionSeverity
Data Sourced
via NVD·02:16 PM
RemedyDescriptionSeverityAffected Software
May 9, 2026
Data Sourced
via Microsoft·08:02 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·08:02 AM
Affected Software
Updated
via Microsoft·08:02 AM
DescriptionSeverity
Frequently Asked Questions
1
What level of access does an attacker need?
Exploitation requires local access and low privileges. The CVSS vector indicates no user interaction is required.
2
Which products are identified as affected?
The affected software listed includes the Linux kernel and Microsoft azl3 kernel version 6.6.137.1-2.