CVE-2026-43466
Linux kernel mlx5e DMA FIFO desync after TX error recovery.
Is CVE-2026-43466 being exploited?
Not confirmed. CVE-2026-43466 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.33% probability of exploitation in the next 30 days.
How severe is CVE-2026-43466?
CVE-2026-43466 is rated High with a CVSS score of 8.2. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-43466?
Yes. A fix has been recorded for CVE-2026-43466. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-43466 affect?
CVE-2026-43466 affects Linux kernel, mlx5e driver. Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-43466?
Apply kernel mlx5e patch; reboot if required
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
TX error recovery desyncs DMA FIFO; may unmap stale DMA addresses, risking memory corruption or data exposure.
Patch when possible
- affected>= db75373c91b0cfb6a68ad6ae88721e4e21ae6261 and < 821f85d619f7f22cda7b9d7de89cf5eeb1d11544
- affected>= db75373c91b0cfb6a68ad6ae88721e4e21ae6261 and < 6eb68ecc5acc3b319986566c595990b8a7265b23
- affected>= db75373c91b0cfb6a68ad6ae88721e4e21ae6261 and < 6f41f7812bfa7f991b732a4b45c5c52fc4be3b4e
- affected>= db75373c91b0cfb6a68ad6ae88721e4e21ae6261 and < 383b37c04a4827ba60b2bafc1a6cdfd995aed58f
- affected>= db75373c91b0cfb6a68ad6ae88721e4e21ae6261 and < 9c5ee9b981ee050b73fdf3f4a2464d6f1a8e10a8
- affected>= db75373c91b0cfb6a68ad6ae88721e4e21ae6261 and < ce1b19dd0684eeb68a124c11085bd611260b36d9
- affected>= db75373c91b0cfb6a68ad6ae88721e4e21ae6261 and < 829efcccfa8f69db5dc8332961295587d218cee6
- affected>= db75373c91b0cfb6a68ad6ae88721e4e21ae6261 and < 1633111d69053512d099658d4a05fc736fab36b0
- affected4.17
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.