CVE detail
CVE-2026-43058
In the Linux kernel, the following vulnerability has been resolved: media: vidtv: fix pass-by-value structs causing MSAN warnings vidtv_ts_null_write_into() and vidtv_ts_pcr_write_into() take their argument structs by value, causing MSAN to report uninit-value warnings. While only vidtv_ts_null_write_into() has triggered a report so far, both functions share the same issue. Fix by passing both structs by const pointer instead, avoiding the stack copy of the struct along with its MSAN shadow and origin metadata. The functions do not modify the structs, which is enforced by the const qualifier.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 24.0 · diversity 10.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
10 source links · newest first
Information published.
vendormsrc.microsoft.comMay 3, 2026, 8:01 AMNo excerpt available.
Patchgit.kernel.orgMay 2, 2026, 7:16 AMNo excerpt available.
Patchgit.kernel.orgMay 2, 2026, 7:16 AMNo excerpt available.
Patchgit.kernel.orgMay 2, 2026, 7:16 AMNo excerpt available.
Patchgit.kernel.orgMay 2, 2026, 7:16 AMNo excerpt available.
Patchgit.kernel.orgMay 2, 2026, 7:16 AMNo excerpt available.
Patchgit.kernel.orgMay 2, 2026, 7:16 AMNo excerpt available.
Patchgit.kernel.orgMay 2, 2026, 7:16 AMNo excerpt available.
Patchgit.kernel.orgMay 2, 2026, 7:16 AMNo excerpt available.
Patchgit.kernel.orgMay 2, 2026, 7:16 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-53355CVSS 9.8 · Critical
In the Linux kernel, the following vulnerability has been resolved: net: rds: clear i_sends on setup unwind The RDS IB connection teardown path is written so it can run during p…
- CVE-2026-53350CVSS 5.5 · Medium
In the Linux kernel, the following vulnerability has been resolved: ASoC: wm_adsp: Fix NULL dereference when removing firmware controls In wm_adsp_control_remove() check that th…
- CVE-2026-53348CVSS 5.5 · Medium
In the Linux kernel, the following vulnerability has been resolved: ASoC: SDCA: fix NULL pointer dereference in sdca_dev_unregister_functions sdca_dev_unregister_functions() ite…
- CVE-2026-53339CVSS 5.5 · Medium
In the Linux kernel, the following vulnerability has been resolved: i2c: qcom-cci: Fix NULL pointer dereference in cci_remove() On all modern platforms Qualcomm CCI controller p…
- CVE-2026-53338CVSS 5.5 · Medium
In the Linux kernel, the following vulnerability has been resolved: net: airoha: Add NULL check for of_reserved_mem_lookup() in airoha_qdma_init_hfwd_queues() of_reserved_mem_lo…
- CVE-2026-53337CVSS 5.5 · Medium
In the Linux kernel, the following vulnerability has been resolved: net: bonding: fix NULL pointer dereference in bond_do_ioctl() In bond_do_ioctl(), slave_dev is obtained via _…