CVE-2026-43164

HIGHNVD 7.57.5
EchelonGraph scoreMEDIUM confidence

Score 7.5 from GitHub Security Advisory (severity: HIGH) published 2026-05-06. NVD baseline CVSS 7.5; sources differ by 0.0.

Triggered by: GitHub Security Advisory CVSS
Sources: epss, ghsa, nvd
7.5EG
EchelonGraph verdictPlan a fixSerious severity, but no confirmed exploitation yet.
  • High severity, but no confirmed exploitation yet
CISA-KEV: Not listedEPSS PROB: 0%CVSS: 7.5Exploit: None knownExposed: 0

No vendor fix yet — apply a workaround or compensating control (WAF / firewall / segmentation) and watch for a patch.

In the Linux kernel, the following vulnerability has been resolved:

udplite: Fix null-ptr-deref in __udp_enqueue_schedule_skb().

syzbot reported null-ptr-deref of udp_sk(sk)->udp_prod_queue. [0]

Since the cited commit, udp_lib_init_sock() can fail, as can udp_init_sock() and udpv6_init_sock().

Let's handle the error in udplite_sk_init() and udplitev6_sk_init().

[0]: BUG: KASAN: null-ptr-deref in instrument_atomic_read include/linux/instrumented.h:82 [inline] BUG: KASAN: null-ptr-deref in atomic_read include/linux/atomic/atomic-instrumented.h:32 [inline] BUG: KASAN: null-ptr-deref in __udp_enqueue_schedule_skb+0x151/0x1480 net/ipv4/udp.c:1719 Read of size 4 at addr 0000000000000008 by task syz.2.18/2944

CPU: 1 UID: 0 PID: 2944 Comm: syz.2.18 Not tainted syzkaller #0 PREEMPTLAZY Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 10/25/2025 Call Trace: dump_stack_lvl+0xe8/0x150 lib/dump_stack.c:120 kasan_report+0xa2/0xe0 mm/kasan/report.c:595 check_region_inline mm/kasan/generic.c:-1 [inline] kasan_check_range+0x264/0x2c0 mm/kasan/generic.c:200 instrument_atomic_read include/linux/instrumented.h:82 [inline] atomic_read include/linux/atomic/atomic-instrumented.h:32 [inline] __udp_enqueue_schedule_skb+0x151/0x1480 net/ipv4/udp.c:1719 __udpv6_queue_rcv_skb net/ipv6/udp.c:795 [inline] udpv6_queue_rcv_one_skb+0xa2e/0x1ad0 net/ipv6/udp.c:906 udp6_unicast_rcv_skb+0x227/0x380 net/ipv6/udp.c:1064 ip6_protocol_deliver_rcu+0xe17/0x1540 net/ipv6/ip6_input.c:438 ip6_input_finish+0x191/0x350 net/ipv6/ip6_input.c:489 NF_HOOK+0x354/0x3f0 include/linux/netfilter.h:318 ip6_input+0x16c/0x2b0 net/ipv6/ip6_input.c:500 NF_HOOK+0x354/0x3f0 include/linux/netfilter.h:318 __netif_receive_skb_one_core net/core/dev.c:6149 [inline] __netif_receive_skb+0xd3/0x370 net/core/dev.c:6262 process_backlog+0x4d6/0x1160 net/core/dev.c:6614 __napi_poll+0xae/0x320 net/core/dev.c:7678 napi_poll net/core/dev.c:7741 [inline] net_rx_action+0x60d/0xdc0 net/core/dev.c:7893 handle_softirqs+0x209/0x8d0 kernel/softirq.c:622 do_softirq+0x52/0x90 kernel/softirq.c:523 __local_bh_enable_ip+0xe7/0x120 kernel/softirq.c:450 local_bh_enable include/linux/bottom_half.h:33 [inline] rcu_read_unlock_bh include/linux/rcupdate.h:924 [inline] __dev_queue_xmit+0x109c/0x2dc0 net/core/dev.c:4856 __ip6_finish_output net/ipv6/ip6_output.c:-1 [inline] ip6_finish_output+0x158/0x4e0 net/ipv6/ip6_output.c:219 NF_HOOK_COND include/linux/netfilter.h:307 [inline] ip6_output+0x342/0x580 net/ipv6/ip6_output.c:246 ip6_send_skb+0x1d7/0x3c0 net/ipv6/ip6_output.c:1984 udp_v6_send_skb+0x9a5/0x1770 net/ipv6/udp.c:1442 udp_v6_push_pending_frames+0xa2/0x140 net/ipv6/udp.c:1469 udpv6_sendmsg+0xfe0/0x2830 net/ipv6/udp.c:1759 sock_sendmsg_nosec net/socket.c:727 [inline] __sock_sendmsg+0xe5/0x270 net/socket.c:742 __sys_sendto+0x3eb/0x580 net/socket.c:2206 __do_sys_sendto net/socket.c:2213 [inline] __se_sys_sendto net/socket.c:2209 [inline] __x64_sys_sendto+0xde/0x100 net/socket.c:2209 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline] do_syscall_64+0xd2/0xf20 arch/x86/entry/syscall_64.c:94 entry_SYSCALL_64_after_hwframe+0x76/0x7e RIP: 0033:0x7f67b4d9c629 Code: ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 44 00 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 e8 ff ff ff f7 d8 64 89 01 48 RSP: 002b:00007f67b5c98028 EFLAGS: 00000246 ORIG_RAX: 000000000000002c RAX: ffffffffffffffda RBX: 00007f67b5015fa0 RCX: 00007f67b4d9c629 RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000003 RBP: 00007f67b4e32b39 R08: 0000000000000000 R09: 0000000000000000 R10: 0000000000040000 R11: 0000000000000246 R12: 0000000000000000 R13: 00007f67b5016038 R14: 00007f67b5015fa0 R15: 00007ffe3cb66dd8

CVSS v3
7.5
EG Score
7.5(medium)
EG Risk
38(Track)
EG Risk 38/100SSVC: Track

EG Risk is EchelonGraph's 0–100 priority score: it fuses intrinsic severity with real-world exploitation and automatability so you can rank equal-severity CVEs and fix the most dangerous first. Higher = act sooner. Distinct from the 0–10 EG Score (severity).

How it’s computed
Severity75% × 45%
Exploitation0% × 40%
Automatability30% × 15%
Action: Routine — remediate on your standard cadence.
EPSS PROB
0%
EPSS %ILE
38%
KEV
Not listed

Published

May 6, 2026

Last Modified

August 5, 2026

Advisory Details (3)

Auto-updated May 13, 2026
No patch confirmed yet.
generic

udplite: Fix null-ptr-deref in __udp_enqueue_schedule_skb(). - kernel/git/stable/linux.git - Linux kernel stable tree

https://git.kernel.org/stable/c/f27030ac5bef47d997cfac05a3d188aa69f4df7f
generic

udplite: Fix null-ptr-deref in __udp_enqueue_schedule_skb(). - kernel/git/stable/linux.git - Linux kernel stable tree

https://git.kernel.org/stable/c/470c7ca2b4c3e3a51feeb952b7f97a775b5c49cd
generic

udplite: Fix null-ptr-deref in __udp_enqueue_schedule_skb(). - kernel/git/stable/linux.git - Linux kernel stable tree

https://git.kernel.org/stable/c/0f13fa087ead642ea1eb5fdb6eb092c913ef06b7

Patch Availability(1)

Vendor / EcosystemFixed in / PatchReleasedSource
linuxKernel @ 6.18.16osv

Patches are aggregated from vendor advisories (Red Hat, Microsoft, Cisco, GitHub) and package ecosystems (OSV, GHSA). Multiple rows for the same upstream release have been deduplicated.

Affected Packages

(1 across 1 ecosystem)
Debian:14(1)
PackageVulnerable rangeFixed inDependents
linux6.12.100-1 ... 6.19~rc8-1~exp1 (116 versions)6.19.6-1

Weakness Classification(1)

MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.

Data Freshness Timeline

(refreshed 7× in last 7d / 29× in last 30d)

Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.

Showing the most recent 100 of 198 total refreshes for this CVE.

  1. 2026-09-13 16:47 UTCEPSS rescore
  2. 2026-09-12 15:01 UTCEPSS rescore
  3. 2026-09-11 16:23 UTCOSV refresh
  4. 2026-09-11 14:53 UTCEPSS rescore
  5. 2026-09-11 09:37 UTCEPSS rescore
  6. 2026-09-10 09:34 UTCEPSS rescore
  7. 2026-09-08 22:00 UTCEPSS rescore
  8. 2026-09-07 16:01 UTCEPSS rescore
  9. 2026-09-06 13:47 UTCEPSS rescore
  10. 2026-09-04 05:06 UTCEPSS rescore
  11. 2026-09-02 14:12 UTCEPSS rescore
  12. 2026-09-01 13:54 UTCEPSS rescore
  13. 2026-08-30 19:17 UTCEPSS rescore
  14. 2026-08-30 01:22 UTCEPSS rescore
  15. 2026-08-28 21:41 UTCEPSS rescore
  16. 2026-08-27 14:25 UTCEPSS rescore
  17. 2026-08-26 14:46 UTCEPSS rescore
  18. 2026-08-25 13:49 UTCEPSS rescore
  19. 2026-08-23 20:12 UTCEG score recompute
  20. 2026-08-23 20:12 UTCGHSA enrichment
  21. 2026-08-23 00:19 UTCEPSS rescore
  22. 2026-08-21 23:49 UTCEPSS rescore
  23. 2026-08-20 22:55 UTCEPSS rescore
  24. 2026-08-19 17:04 UTCEPSS rescore
  25. 2026-08-18 13:48 UTCEPSS rescore
Show 75 more
  1. 2026-08-17 13:47 UTCEPSS rescore
  2. 2026-08-17 12:57 UTCEG score recompute
  3. 2026-08-17 12:57 UTCGHSA enrichment
  4. 2026-08-16 14:56 UTCEPSS rescore
  5. 2026-08-16 04:54 UTCEG score recompute
  6. 2026-08-16 04:54 UTCGHSA enrichment
  7. 2026-08-16 02:14 UTCEPSS rescore
  8. 2026-08-15 02:04 UTCEG score recompute
  9. 2026-08-15 02:03 UTCGHSA enrichment
  10. 2026-08-15 01:30 UTCEPSS rescore
  11. 2026-08-14 14:45 UTCGHSA enrichment
  12. 2026-08-14 03:29 UTCEG score recompute
  13. 2026-08-14 03:29 UTCGHSA enrichment
  14. 2026-08-13 22:00 UTCEPSS rescore
  15. 2026-08-13 04:17 UTCGHSA enrichment
  16. 2026-08-12 17:01 UTCEG score recompute
  17. 2026-08-12 17:01 UTCGHSA enrichment
  18. 2026-08-12 13:51 UTCEPSS rescore
  19. 2026-08-11 16:00 UTCEG score recompute
  20. 2026-08-11 16:00 UTCGHSA enrichment
  21. 2026-08-11 13:43 UTCEPSS rescore
  22. 2026-08-11 01:32 UTCEG score recompute
  23. 2026-08-11 01:32 UTCGHSA enrichment
  24. 2026-08-11 00:00 UTCEPSS rescore
  25. 2026-08-10 12:44 UTCGHSA enrichment
  26. 2026-08-10 01:10 UTCGHSA enrichment
  27. 2026-08-09 13:53 UTCEG score recompute
  28. 2026-08-09 13:53 UTCGHSA enrichment
  29. 2026-08-09 13:46 UTCEPSS rescore
  30. 2026-08-09 02:36 UTCEG score recompute
  31. 2026-08-09 02:36 UTCGHSA enrichment
  32. 2026-08-08 16:37 UTCEPSS rescore
  33. 2026-08-08 11:44 UTCGHSA enrichment
  34. 2026-08-08 00:28 UTCEG score recompute
  35. 2026-08-08 00:28 UTCGHSA enrichment
  36. 2026-08-07 13:11 UTCGHSA enrichment
  37. 2026-08-07 01:54 UTCEG score recompute
  38. 2026-08-07 01:54 UTCGHSA enrichment
  39. 2026-08-06 13:46 UTCEPSS rescore
  40. 2026-08-06 12:26 UTCGHSA enrichment
  41. 2026-08-06 01:08 UTCEG score recompute
  42. 2026-08-06 01:08 UTCGHSA enrichment
  43. 2026-08-05 19:17 UTCEPSS rescore
  44. 2026-08-05 13:52 UTCEG score recompute
  45. 2026-08-05 13:52 UTCGHSA enrichment
  46. 2026-08-04 15:10 UTCEPSS rescore
  47. 2026-08-04 10:38 UTCEPSS rescore
  48. 2026-08-03 19:53 UTCEG score recompute
  49. 2026-08-03 19:53 UTCGHSA enrichment
  50. 2026-08-03 10:36 UTCEPSS rescore
  51. 2026-08-03 03:59 UTCGHSA enrichment
  52. 2026-08-02 16:25 UTCGHSA enrichment
  53. 2026-08-02 05:09 UTCEG score recompute
  54. 2026-08-02 05:09 UTCGHSA enrichment
  55. 2026-08-01 04:16 UTCEPSS rescore
  56. 2026-07-30 16:28 UTCEPSS rescore
  57. 2026-07-30 01:30 UTCEPSS rescore
  58. 2026-07-28 15:36 UTCEPSS rescore
  59. 2026-07-27 14:13 UTCEPSS rescore
  60. 2026-07-26 14:54 UTCEPSS rescore
  61. 2026-07-26 14:54 UTCEPSS rescore
  62. 2026-07-25 14:18 UTCEPSS rescore
  63. 2026-07-24 14:17 UTCEPSS rescore
  64. 2026-07-23 14:18 UTCEPSS rescore
  65. 2026-07-23 03:13 UTCEG score recompute
  66. 2026-07-22 14:08 UTCEPSS rescore
  67. 2026-07-21 15:24 UTCEPSS rescore
  68. 2026-07-20 22:32 UTCOSV refresh
  69. 2026-07-20 17:08 UTCEPSS rescore
  70. 2026-07-19 14:31 UTCEPSS rescore
  71. 2026-07-19 02:29 UTCEPSS rescore
  72. 2026-07-18 10:04 UTCEPSS rescore
  73. 2026-07-16 17:03 UTCEPSS rescore
  74. 2026-07-15 16:57 UTCEPSS rescore
  75. 2026-07-15 02:00 UTCEPSS rescore

Frequently asked(5)

What is CVE-2026-43164?
CVE-2026-43164 is a high vulnerability published on May 6, 2026. In the Linux kernel, the following vulnerability has been resolved: udplite: Fix null-ptr-deref in udpenqueueschedule_skb(). syzbot reported null-ptr-deref of udpsk(sk)->udpprod_queue. [0] Since the cited commit, udplibinit_sock() can fail, as can udpinitsock() and udpv6initsock(). Let's handle the…
When was CVE-2026-43164 disclosed?
CVE-2026-43164 was first published in the National Vulnerability Database on May 6, 2026, with the most recent update on August 5, 2026. EchelonGraph re-ingests CVE updates from NVD on a 2-hour cycle, so this page reflects the latest published state.
Is CVE-2026-43164 actively exploited?
CVE-2026-43164 is not currently on CISA's Known Exploited Vulnerabilities catalog. FIRST EPSS estimates a 0% probability of exploitation in the next 30 days, which ranks it in the top 62.0% of all scored CVEs.
What is the CVSS score of CVE-2026-43164?
CVE-2026-43164 has a CVSS v3 base score of 7.5 (NVD).
How do I remediate CVE-2026-43164?
Patch to the fixed version published by the affected vendor. Where vendor advisories exist for CVE-2026-43164, EchelonGraph cross-links them in the Vendor Advisories panel below — those typically contain the canonical remediation steps, fixed version numbers, and any vendor-specific mitigations.

Dependency Blast Radius

See which npm, PyPI, Go, and Maven packages are affected by CVE-2026-43164

Explore →

Is Your Infrastructure Affected by CVE-2026-43164?

EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.