CVE-2026-43056

7.8

Linux · kernel

A use-after-free vulnerability exists in the Linux kernel Microsoft Azure Network Adapter driver error handling path, potentially leading to local privilege escalation.

Executive summary

A use-after-free vulnerability in the Linux kernel Microsoft Azure Network Adapter driver allows local attackers with low privileges to achieve high impact on confidentiality, integrity, and availability.

Vulnerability

This is a use-after-free flaw located in the Microsoft Azure Network Adapter driver error handling path of the add_adev function, requiring low local privileges to trigger.

Business impact

A successful exploit of this vulnerability can allow a locally authenticated attacker to compromise system integrity, access sensitive data, and cause complete system denial of service. The CVSS score of 7.8 reflects a high severity risk that threatens foundational host operating system security, demanding prompt attention from infrastructure and security teams.

Remediation

Immediate Action: Apply the vendor-provided kernel updates by upgrading to version 6.6.134, 6.12.81, 6.18.22, 6.19.12, or later as specified by your distribution.

Proactive Monitoring: Monitor system logs for kernel panics, segmentation faults, and unusual process behavior associated with the Microsoft Azure Network Adapter driver.

Compensating Controls: Restrict local shell access and enforce the principle of least privilege to prevent unauthorized users from executing code on vulnerable hosts.

Exploitation status

Public Exploit Available: No

Analyst recommendation

This high-severity flaw requires immediate remediation to safeguard host operating system integrity. System administrators must prioritize applying the updated kernel packages to all affected Linux environments to eliminate the underlying use-after-free risk.

More Linux CVEs

Sources