CVE-2026-43184
Analyzed Analyzed - Analysis Complete
Zeroed Response Buffer in Linux Kernel rnbd-srv

Publication date: 2026-05-06

Last updated on: 2026-05-11

Assigner: kernel.org

Description
In the Linux kernel, the following vulnerability has been resolved: rnbd-srv: Zero the rsp buffer before using it Before using the data buffer to send back the response message, zero it completely. This prevents any stray bytes to be picked up by the client side when there the message is exchanged between different protocol versions.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-05-06
Last Modified
2026-05-11
Generated
2026-06-16
AI Q&A
2026-05-06
EPSS Evaluated
2026-06-14
NVD
EUVD
Affected Vendors & Products
Showing 7 associated CPEs
Vendor Product Version / Range
linux linux_kernel From 6.2 (inc) to 6.6.128 (exc)
linux linux_kernel From 6.7 (inc) to 6.12.75 (exc)
linux linux_kernel From 6.13 (inc) to 6.18.16 (exc)
linux linux_kernel From 6.19 (inc) to 6.19.6 (exc)
linux linux_kernel From 5.11 (inc) to 5.15.202 (exc)
linux linux_kernel From 5.16 (inc) to 6.1.165 (exc)
linux linux_kernel From 5.8 (inc) to 5.10.252 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability exists in the Linux kernel component called rnbd-srv. It involves the rsp buffer, which is used to send back response messages. Before this fix, the rsp buffer was not completely cleared (zeroed) before use, which could cause leftover data (stray bytes) from previous messages to be included in the response. This could happen especially when messages are exchanged between different protocol versions.

The fix involves zeroing the rsp buffer completely before using it to ensure no unintended data is sent back to the client.

Impact Analysis

If exploited, this vulnerability could cause unintended data from previous communications to be leaked to clients. This could potentially expose sensitive or confidential information that was stored in the buffer from earlier messages.

Such data leakage might lead to privacy concerns or information disclosure, depending on what data is inadvertently sent.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-43184. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart