Back to overview

CVE-2026-43186

CRITICAL
9.8
CVSS 3.1
Description
In the Linux kernel, the following vulnerability has been resolved: ipv6: ioam: fix heap buffer overflow in __ioam6_fill_trace_data() On the receive path, __ioam6_fill_trace_data() uses trace->nodelen to decide how much data to write for each node. It trusts this field as-is from the incoming packet, with no consistency check against trace->type (the 24-bit field that tells which data items are present). A crafted packet can set nodelen=0 while setting type bits 0-21, causing the function to write ~100 bytes past the allocated region (into skb_shared_info), which corrupts adjacent heap memory and leads to a kernel panic. Add a shared helper ioam6_trace_compute_nodelen() in ioam6.c to derive the expected nodelen from the type field, and use it: - in ioam6_iptunnel.c (send path, existing validation) to replace the open-coded computation; - in exthdrs.c (receive path, ipv6_hop_ioam) to drop packets whose nodelen is inconsistent with the type field, before any data is written. Per RFC 9197, bits 12-21 are each short (4-octet) fields, so they are included in IOAM6_MASK_SHORT_FIELDS (changed from 0xff100000 to 0xff1ffc00).

Metadata

CVE ID
CVE-2026-43186
State
PUBLISHED
Assigner
Linux
Reserved
2026-05-01 14:12 UTC
Published
2026-05-06 11:27 UTC
Last updated
2026-05-11 22:19 UTC
Vendor / Product
Linux / Linux
Sources
cve.org  ·  NVD

Severity & Metrics

9.8 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products (2)
VendorProductPlatformVersions
Linux Linux 9ee11f0fff205b4b3df9750bff5e94f97c71b6a0 < f4d9d4b8fd839719d564651671e24c62c545c23b, 9ee11f0fff205b4b3df9750bff5e94f97c71b6a0 < fb3c662fafebc5b9d74417ed1de8759f6bb72143, 9ee11f0fff205b4b3df9750bff5e94f97c71b6a0 < 632d233cf2e64a46865ae2c064ae3c9df7c8864f, 9ee11f0fff205b4b3df9750bff5e94f97c71b6a0 < 0591d6509c2ff13f09ea2998434aba0c0472e978 …
Linux Linux 5.15, 0 < 5.15, 5.15.202 ≤ 5.15.*, 6.1.165 ≤ 6.1.* …
CVSS scores (1)
ScoreSeverityVersionSourceVector
9.8 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Back to overview