CVE-2026-43466 - Vulnerability Analysis
HighCVSS: 8.2Last Updated: May 11, 2026
Linux kernel net/mlx5e - Denial of Service
Overview
Linux kernel net/mlx5e contains a DMA FIFO desynchronization caused by improper reset of dma_fifo_cc during TX error CQE recovery, letting kernel processes experience stale DMA address unmapping, exploit requires triggering TX error CQE.
Severity & Score
Impact
Kernel processes may unmap stale DMA addresses causing memory corruption or instability, potentially leading to denial of service or system crashes.
Mitigation
Update to the latest Linux kernel version containing the fix for DMA FIFO desync in net/mlx5e.
References
- https://git.kernel.org/stable/c/1633111d69053512d099658d4a05fc736fab36b0
- https://git.kernel.org/stable/c/383b37c04a4827ba60b2bafc1a6cdfd995aed58f
- https://git.kernel.org/stable/c/6eb68ecc5acc3b319986566c595990b8a7265b23
- https://git.kernel.org/stable/c/6f41f7812bfa7f991b732a4b45c5c52fc4be3b4e
- https://git.kernel.org/stable/c/821f85d619f7f22cda7b9d7de89cf5eeb1d11544
- https://git.kernel.org/stable/c/829efcccfa8f69db5dc8332961295587d218cee6
- https://git.kernel.org/stable/c/9c5ee9b981ee050b73fdf3f4a2464d6f1a8e10a8
- https://git.kernel.org/stable/c/ce1b19dd0684eeb68a124c11085bd611260b36d9
Social Media Activity(2 posts)
š CVE-2026-43466 - High (8.2) In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Fix DMA FIFO desync on error CQE SQ recovery In case of a TX error CQE, a recovery flow is triggered, mlx5e_reset_txqsq_cc_pc() resets dma_fifo_cc to 0 but not dma_fi... š https://www.thehackerwire.com/vulnerability/CVE-2026-43466/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
View original postš CVE-2026-43466 - High (8.2) In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Fix DMA FIFO desync on error CQE SQ recovery In case of a TX error CQE, a recovery flow is triggered, mlx5e_reset_txqsq_cc_pc() resets dma_fifo_cc to 0 but not dma_fi... š https://www.thehackerwire.com/vulnerability/CVE-2026-43466/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
View original postRelated Resources
Details
- CVE ID
- CVE-2026-43466
- Severity
- High
- CVSS Score
- 8.2
- Type
- undefined
- Status
- new
- EPSS
- 5.2%
- Social Posts
- 2
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H