CVE-2026-43291
Kernel NFC/NCI packet validation flaw may access uninitialized data.
Is CVE-2026-43291 being exploited?
Not confirmed. CVE-2026-43291 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.27% probability of exploitation in the next 30 days.
How severe is CVE-2026-43291?
CVE-2026-43291 is rated High with a CVSS score of 8.3. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-43291?
Yes. A fix has been recorded for CVE-2026-43291. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-43291 affect?
CVE-2026-43291 affects Linux kernel, NFC/NCI subsystem. Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-43291?
Update to patched kernel; reboot to apply fix.
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Local kernel data access in NFC/NCI path could cause memory corruption or crash.
Patch when possible
- affected>= 8fcc7315a10a84264e55bb65ede10f0af20a983f and < a24a8a582da4426b2042e510a1080df84083b51d
- affected>= bfdda0123dde406dbff62e7e9136037e97998a15 and < f5218426f765eee22e178df9c126d974792fb6a5
- affected>= 0ba68bea1e356f466ad29449938bea12f5f3711f and < ad058a4317db7fdb3f09caa6ed536d24a62ce6a0
- affected>= 74837bca0748763a77f77db47a0bdbe63b347628 and < 3b91160e9a91b5a2662875417dc42dc5b0bf03ea
- affected>= 9c328f54741bd5465ca1dc717c84c04242fac2e1 and < c692db813a7e3b7c3c17d6e9a3ad2a018bf1142b
- affected>= 9c328f54741bd5465ca1dc717c84c04242fac2e1 and < 498fc5d0d650c77e87fcc73808d4f43240c21805
- affected>= 9c328f54741bd5465ca1dc717c84c04242fac2e1 and < 571dcbeb8e635182bb825ae758399831805693c2
- affectedc395d1e548cc68e84584ffa2e3ca9796a78bf7b9
- affected>= 5.15.195 and < 5.15.202
- affected>= 6.1.156 and < 6.1.165
- affected>= 6.6.112 and < 6.6.128
- affected>= 6.12.53 and < 6.12.75
- affected>= 6.17.3 and < 6.18
- affected6.18
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.