{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.19.12-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  io_uring/rsrc: reject zero-length fixed buffer import  validate_fixed_range() admits buf_addr at the exact end of the registered region when len is zero, because the check uses strict greater-than (buf_end \u003e imu-\u003eubuf + imu-\u003elen).  io_import_fixed() then computes offset == imu-\u003elen, which causes the bvec skip logic to advance past the last bio_vec entry and read bv_offset from out-of-bounds slab memory.  Return early from io_import_fixed() when len is zero.  A zero-length import has no data to transfer and should not walk the bvec array at all.    BUG: KASAN: slab-out-of-bounds in io_import_reg_buf+0x697/0x7f0   Read of size 4 at addr ffff888002bcc254 by task poc/103   Call Trace:    io_import_reg_buf+0x697/0x7f0    io_write_fixed+0xd9/0x250    __io_issue_sqe+0xad/0x710    io_issue_sqe+0x7d/0x1100    io_submit_sqes+0x86a/0x23c0    __do_sys_io_uring_enter+0xa98/0x1590   Allocated by task 103:   The buggy address is located 12 bytes to the right of    allocated 584-byte region [ffff888002bcc000, ffff888002bcc248)",
  "id": "DEBIAN-CVE-2026-43006",
  "modified": "2026-09-14T16:47:45.934469590Z",
  "published": "2026-05-01T15:16:44.450Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-43006"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H",
      "type": "CVSS_V3"
    }
  ],
  "upstream": [
    "CVE-2026-43006"
  ]
}