Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3376 articles · 142302 vulns · 36/41 feeds (7d)
← Back to list
—
CVE-2026-43297EXPLOITEDPATCHED
linux · linux kernel

media: rockchip: rga: Fix possible ERR_PTR dereference in rga_buf_init()

Description

A vulnerability categorized as critical has been discovered in Linux Kernel up to 6.12.74/6.18.15/6.19.5. Affected by this vulnerability is the function rga_buf_init of the component media. The manipulation results in buffer overflow.

Affected Products

VendorProductVersions
linuxlinux kernel6040702ade234c8212dcfdef85e2f5549aa2f0f5, 6040702ade234c8212dcfdef85e2f5549aa2f0f5, 6040702ade234c8212dcfdef85e2f5549aa2f0f5, 6040702ade234c8212dcfdef85e2f5549aa2f0f5, 6.8, 6.12.74, 6.18.15, 6.19.5

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
open sourceopen source linux kernelcert_advisory90%

References

  • https://git.kernel.org/stable/c/5da29ade540b51763b950987bd410add7edaf3d1
  • https://git.kernel.org/stable/c/1af2853b4e97fd95262fdef311b2334337069bc9
  • https://git.kernel.org/stable/c/aa22221c5dc695a3d479e1e1b63f0c0e9eb29dbf
  • https://git.kernel.org/stable/c/81f8e0e6a2e115df9274d0289779f8fca694479c

Related News (3 articles)

Tier B
BSI Advisories12h ago
[NEU] [mittel] Linux Kernel: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
VulDB3d ago
CVE-2026-43297 | Linux Kernel up to 6.12.74/6.18.15/6.19.5 media rga_buf_init buffer overflow
→ No new info (linked only)
Tier C
Linux Kernel CVEs3d ago
CVE-2026-43297: media: rockchip: rga: Fix possible ERR_PTR dereference in rga_buf_init()
→ No new info (linked only)
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
5da29ade540b51763b950987bd410add7edaf3d11af2853b4e97fd95262fdef311b2334337069bc9aa22221c5dc695a3d479e1e1b63f0c0e9eb29dbf81f8e0e6a2e115df9274d0289779f8fca694479c06.12.756.18.166.19.67.0
PublishedMay 8, 2026
Last enriched3d agov2
Trending Score61
Source articles3
Independent3
Info Completeness7/14
Missing: cvss, epss, cwe, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

IMPORTANTCVE-2026-43284EXPKEV
xfrm: esp: avoid in-place decrypt on shared skb frags
Trending: 133
HIGHCVE-2026-43500EXPKEV
rxrpc: Also unshare DATA/RESPONSE packets when paged frags are present
Trending: 117
HIGHCVE-2026-31431EXPKEV
crypto: algif_aead - Revert to operating out-of-place
Trending: 116
CRITICALCVE-2025-71296EXP
drm/tests: shmem: Hold reservation lock around purge
Trending: 61
CRITICALCVE-2026-43295EXP
rapidio: replace rio_free_net() with kfree() in rio_scan_alloc_net()
Trending: 61

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
May 8, 2026
Discovered by ZDM
May 8, 2026
Actively Exploited
May 8, 2026
Patch Available
May 8, 2026
Updated: description, severity, affectedVersions, activelyExploited
May 8, 2026

Version History

v2
Last enriched 3d ago
v2Tier C3d ago

Updated severity to CRITICAL, added affected versions, and corrected exploit availability.

descriptionseverityaffectedVersionsactivelyExploited
via VulDB
v13d ago

Initial creation