Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

CVE-2026-43037

ip6_tunnel: clear skb2->cb[] in ip4ip6_err()
Back to all
CVE

CVE-2026-43037

ip6_tunnel: clear skb2->cb[] in ip4ip6_err()

In the Linux kernel, the following vulnerability has been resolved:

ip6tunnel: clear skb2->cb[] in ip4ip6err()

Oskar Kjos reported the following problem.

ip4ip6err() calls icmpsend() on a cloned skb whose cb[] was written

by the IPv6 receive path as struct inet6skbparm. icmp_send() passes

IPCB(skb2) to _ipoptions_echo(), which interprets that cb[] region

as struct inetskbparm (IPv4). The layouts differ: inet6skbparm.nhoff

at offset 14 overlaps inetskbparm.opt.rr, producing a non-zero rr

value. _ipoptions_echo() then reads optlen from attacker-controlled

packet data at sptr[rr+1] and copies that many bytes into dopt->__data,

a fixed 40-byte stack buffer (IPOPTIONSDATAFIXEDSIZE).

To fix this we clear skb2->cb[], as suggested by Oskar Kjos.

Also add minimal IPv4 header validation (version == 4, ihl >= 5).

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
9.8
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
0
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
-

Related Resources

No items found.

References

https://git.kernel.org/stable/c/1063515ce15ff31065c4e7f8265f4c2fd3c54876, https://git.kernel.org/stable/c/2cc6e3b0fe0f0242d1f530a93a4924f48ab85ba5, https://git.kernel.org/stable/c/2edfa31769a4add828a7e604b21cb82aaaa05925, https://git.kernel.org/stable/c/4a622658f384b03560834cbe8ffcfe69a278f7c8, https://git.kernel.org/stable/c/590f622669b97eaf7b57a1de7b0a6e68c5d8b2c3, https://git.kernel.org/stable/c/a0c4ce9900a108eaf55d0f3b399cb55999647d39, https://git.kernel.org/stable/c/d6621f60192fe10c047a4487be42a6f4c150707f, https://git.kernel.org/stable/c/ea9f65b27c8404e164848ebff1443310fd187629, https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-43037.json, https://access.redhat.com/errata/RHSA-2026:22900, https://access.redhat.com/errata/RHSA-2026:22940, https://access.redhat.com/errata/RHSA-2026:22964, https://access.redhat.com/errata/RHSA-2026:23224, https://access.redhat.com/errata/RHSA-2026:23237, https://access.redhat.com/errata/RHSA-2026:24343, https://access.redhat.com/errata/RHSA-2026:25120, https://access.redhat.com/errata/RHSA-2026:25121, https://access.redhat.com/errata/RHSA-2026:25181, https://access.redhat.com/errata/RHSA-2026:25186, https://access.redhat.com/errata/RHSA-2026:25191, https://access.redhat.com/errata/RHSA-2026:25193, https://access.redhat.com/errata/RHSA-2026:25200, https://access.redhat.com/errata/RHSA-2026:25217, https://access.redhat.com/errata/RHSA-2026:25533, https://access.redhat.com/errata/RHSA-2026:25534, https://access.redhat.com/errata/RHSA-2026:26528, https://access.redhat.com/errata/RHSA-2026:26535, https://access.redhat.com/errata/RHSA-2026:26542, https://access.redhat.com/errata/RHSA-2026:27719, https://access.redhat.com/errata/RHSA-2026:27729, https://access.redhat.com/errata/RHSA-2026:28738, https://access.redhat.com/errata/RHSA-2026:28740, https://access.redhat.com/errata/RHSA-2026:28741, https://access.redhat.com/errata/RHSA-2026:28742, https://access.redhat.com/errata/RHSA-2026:28748, https://access.redhat.com/errata/RHSA-2026:28749, https://access.redhat.com/errata/RHSA-2026:28750, https://access.redhat.com/errata/RHSA-2026:28887, https://access.redhat.com/errata/RHSA-2026:28962, https://access.redhat.com/errata/RHSA-2026:33486, https://access.redhat.com/errata/RHSA-2026:34098, https://access.redhat.com/security/cve/CVE-2026-43037, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/43xxx/CVE-2026-43037.json, https://nvd.nist.gov/vuln/detail/CVE-2026-43037, https://bugzilla.redhat.com/show_bug.cgi?id=2464351, https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Severity

9.8

CVSS Score
0
10

Basic Information

Base CVSS
9.8
EPSS Probability
0.00563%
EPSS Percentile
0.4306%
Introduced Version
c4d3efafcc933fd2ffd169d7dc4f980393a13796,2.6.22,5.11.0,5.16.0,6.2.0,6.7.0,6.13.0,6.19.0,0
Fix Available
2edfa31769a4add828a7e604b21cb82aaaa05925,5.10.253,5.15.203,6.1.168,6.6.134,6.12.81,6.18.22,6.19.12,0:4.18.0-553.132.1.rt7.473.el8_10,0:1-4.el8_10,0:1-1.el8_10,0:1-11.el8_10,0:1-8.el8_10,0:1-6.el8_10,0:4.18.0-553.132.1.el8_10,0:5.14.0-687.15.1.el9_8,0:1-1.el9_8,6.1.170-1,5.10.257-1,6.1.170-1~deb11u1,6.12.85-1,0:6.8.0-134.134,0:6.17.0-40.40~24.04.1,0:6.8.0-1060.63,0:6.17.0-1019.19~24.04.1,0:6.8.0-1063.69,0:6.17.0-1020.22~24.04.1,0:6.8.0-1058.64,0:6.8.0-1045.48,0:6.8.0-1060.61,0:6.8.0-134.134.1,0:6.8.0-1058.61,0:6.8.0-1058.61.1,0:6.8.0-1029.30,0:6.8.0-1057.58,0:6.17.0-1018.18~24.04.1,0:6.17.0-1028.28,0:6.8.0-1060.64,0:6.8.0-1032.33,0:6.17.0-1026.26,0:4.15.0-253.265,0:4.15.0-1176.181,0:4.15.0-1194.207,0:4.15.0-1204.219,0:4.15.0-1187.204,0:4.15.0-1156.167,0:5.15.0-185.195~20.04.1,0:5.15.0-1111.118~20.04.1,0:5.15.0-1116.125~20.04.1,0:5.15.0-1111.121~20.04.1,0:5.15.0-1105.109~20.04.1,0:5.15.0-1106.112~20.04.1,0:5.15.0-183.193~20.04.1,0:5.15.0-1063.63~20.04.1,0:5.15.0-1108.114~20.04.1,0:5.15.0-185.195,0:5.15.0-1103.108,0:5.15.0-1111.118,0:6.8.0-1060.63~22.04.1,0:5.15.0-1116.125,0:5.15.0-1111.121,0:6.8.0-1063.69~22.04.1,0:5.15.0-1107.113,0:5.15.0-1094.102,0:5.15.0-1105.109,0:6.8.0-1060.61~22.04.1,0:5.15.0-1106.112,0:5.15.0-183.193,0:6.8.0-134.134.1~22.04.1,0:5.15.0-1106.107,0:6.8.0-1058.61~22.04.1,0:5.15.0-1063.63,0:5.15.0-1052.52,0:5.15.0-1108.114,0:6.8.0-1057.58~22.04.1,0:5.15.0-1105.108,0:5.15.0-1074.78,0:6.12.0-204.92.4.2.el9uek,0:5.14.0-687.17.1.el9_8,0:6.12.0-203.76.7.5.el9uek,0:5.4.17-2136.357.3.1.el8uek,0:5.4.17-2136.357.3.1.el7uek,1:6.1.168-202.320.amzn2023,1:1.0-0.amzn2023,1:6.12.83-113.160.amzn2023,1:6.18.25-52.107.amzn2023,0:5.10.253-252.1015.amzn2,0:1.0-0.amzn2,0:5.15.204-143.230.amzn2

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading