Back to overview

CVE-2026-43341

CRITICAL
9.8
CVSS 3.1
Description
In the Linux kernel, the following vulnerability has been resolved: net/ipv6: ioam6: prevent schema length wraparound in trace fill ioam6_fill_trace_data() stores the schema contribution to the trace length in a u8. With bit 22 enabled and the largest schema payload, sclen becomes 1 + 1020 / 4, wraps from 256 to 0, and bypasses the remaining-space check. __ioam6_fill_trace_data() then positions the write cursor without reserving the schema area but still copies the 4-byte schema header and the full schema payload, overrunning the trace buffer. Keep sclen in an unsigned int so the remaining-space check and the write cursor calculation both see the full schema length.

Metadata

CVE ID
CVE-2026-43341
State
PUBLISHED
Assigner
Linux
Reserved
2026-05-01 14:12 UTC
Published
2026-05-08 13:37 UTC
Last updated
2026-06-19 11:58 UTC
Vendor / Product
Linux / Linux
Sources
cve.org  ·  NVD

Severity & Metrics

9.8 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products (2)
VendorProductPlatformVersions
Linux Linux 8c6f6fa6772696be0c047a711858084b38763728 < d3a1fb2ca323d7a4e10ab3afbfa25e6d8921e4f2, 8c6f6fa6772696be0c047a711858084b38763728 < e96d48b37708d53cbdc47f6f60b0714fc4a5f596, 8c6f6fa6772696be0c047a711858084b38763728 < d1b041080086e91d3733a5438a8c51ad5d3d8e09, 8c6f6fa6772696be0c047a711858084b38763728 < 77695a69baca9b99d95fad09fc78c2318736604f …
Linux Linux 5.15, 0 < 5.15, 5.15.210 ≤ 5.15.*, 6.1.168 ≤ 6.1.* …
CVSS scores (1)
ScoreSeverityVersionSourceVector
9.8 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Back to overview