bpf: reject direct access to nullable PTR_TO_BUF pointers
Published May 8, 2026
5.5
MEDIUMCVSS 3.1
EPSS 0.16%
Description
check_mem_access() matches PTR_TO_BUF via base_type() which strips PTR_MAYBE_NULL, allowing direct dereference without a null check.
Map iterator ctx->key and ctx->value are PTR_TO_BUF | PTR_MAYBE_NULL. On stop callbacks these are NULL, causing a kernel NULL dereference.
Add a type_may_be_null() guard to the PTR_TO_BUF branch, matching the existing PTR_TO_BTF_ID pattern.
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints-
- Version
-
- Version 5.15.37StatusaffectedConstraints<5.15.203
- Version 5.16.11StatusaffectedConstraints<5.17
- Version
-
- Version 5.17StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<5.17
- Version 5.15.203StatusunaffectedConstraints<=5.15.*
- Version 6.1.168StatusunaffectedConstraints<=6.1.*
- Version 6.12.81StatusunaffectedConstraints<=6.12.*
- Version 6.18.22StatusunaffectedConstraints<=6.18.*
- Version 6.19.12StatusunaffectedConstraints<=6.19.*
- Version 6.6.134StatusunaffectedConstraints<=6.6.*
- Version 7.0StatusunaffectedConstraints<=*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux | unaffected |
| ||||||||||||||||||||||||||||||
| Linux | Linux | unaffected |
| ||||||||||||||||||||||||||||||
| Linux | Linux | affected |
|
- ≥ 5.15.37 · < 5.15.203
- ≥ 5.16.11 · < 6.1.168
- ≥ 6.2 · < 6.6.134
- ≥ 6.7 · < 6.12.81
- ≥ 6.13 · < 6.18.22
- ≥ 6.19 · < 6.19.12
- 7.0
- 7.0
- 7.0
- 7.0
- 7.0
- 7.0
No data.
Red Hat Enterprise Linux 10
kernel
Fix deferred
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Fix deferred
Red Hat Enterprise Linux 8
kernel-rt
Fix deferred
Red Hat Enterprise Linux 9
kernel
Fix deferred
Red Hat Enterprise Linux 9
kernel-rt
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | kernel | Fix deferred | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | kernel | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (12)
- https://access.redhat.com/security/cve/CVE-2026-43333 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2468128 Issue Tracking
- https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-43333.mbox
- https://git.kernel.org/stable/c/10bc4a4dcded509c5d5c67d497900c3922c604cd Patch
- https://git.kernel.org/stable/c/21a10c06ffae24cb01fd174a7ab7736001d2ea56 Patch
- https://git.kernel.org/stable/c/4f6c99dc0420f1a3d671c1b8ab8a7ac84d9cba09 Patch
- https://git.kernel.org/stable/c/63276547debc4d8a73eefb2c5273b2a905c961b0 Patch
- https://git.kernel.org/stable/c/70abd9d118da2f56beb4ec22e3a29becae373535 Patch
- https://git.kernel.org/stable/c/8755066f7bd0f4ac46a29d1708c7b20894539252 Patch
- https://git.kernel.org/stable/c/b0db1accbc7395657c2b79db59fa9fae0d6656f3 Patch
- https://nvd.nist.gov/vuln/detail/CVE-2026-43333
- https://www.cve.org/CVERecord?id=CVE-2026-43333
Change history (0)
No recorded changes yet.