CVE-2026-43037
In the Linux kernel, the following vulnerability has been resolved:
ip6tunnel: clear skb2->cb[] in ip4ip6err()
Oskar Kjos reported the following problem.
ip4ip6err() calls icmpsend() on a cloned skb whose cb[] was written
by the IPv6 receive path as struct inet6skbparm. icmp_send() passes
IPCB(skb2) to _ipoptions_echo(), which interprets that cb[] region
as struct inetskbparm (IPv4). The layouts differ: inet6skbparm.nhoff
at offset 14 overlaps inetskbparm.opt.rr, producing a non-zero rr
value. _ipoptions_echo() then reads optlen from attacker-controlled
packet data at sptr[rr+1] and copies that many bytes into dopt->__data,
a fixed 40-byte stack buffer (IPOPTIONSDATAFIXEDSIZE).
To fix this we clear skb2->cb[], as suggested by Oskar Kjos.
Also add minimal IPv4 header validation (version == 4, ihl >= 5).
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://git.kernel.org/stable/c/1063515ce15ff31065c4e7f8265f4c2fd3c54876, https://git.kernel.org/stable/c/2cc6e3b0fe0f0242d1f530a93a4924f48ab85ba5, https://git.kernel.org/stable/c/2edfa31769a4add828a7e604b21cb82aaaa05925, https://git.kernel.org/stable/c/4a622658f384b03560834cbe8ffcfe69a278f7c8, https://git.kernel.org/stable/c/590f622669b97eaf7b57a1de7b0a6e68c5d8b2c3, https://git.kernel.org/stable/c/a0c4ce9900a108eaf55d0f3b399cb55999647d39, https://git.kernel.org/stable/c/d6621f60192fe10c047a4487be42a6f4c150707f, https://git.kernel.org/stable/c/ea9f65b27c8404e164848ebff1443310fd187629, https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-43037.json, https://access.redhat.com/errata/RHSA-2026:22900, https://access.redhat.com/errata/RHSA-2026:22940, https://access.redhat.com/errata/RHSA-2026:22964, https://access.redhat.com/errata/RHSA-2026:23224, https://access.redhat.com/errata/RHSA-2026:23237, https://access.redhat.com/errata/RHSA-2026:24343, https://access.redhat.com/errata/RHSA-2026:25120, https://access.redhat.com/errata/RHSA-2026:25121, https://access.redhat.com/errata/RHSA-2026:25181, https://access.redhat.com/errata/RHSA-2026:25186, https://access.redhat.com/errata/RHSA-2026:25191, https://access.redhat.com/errata/RHSA-2026:25193, https://access.redhat.com/errata/RHSA-2026:25200, https://access.redhat.com/errata/RHSA-2026:25217, https://access.redhat.com/errata/RHSA-2026:25533, https://access.redhat.com/errata/RHSA-2026:25534, https://access.redhat.com/errata/RHSA-2026:26528, https://access.redhat.com/errata/RHSA-2026:26535, https://access.redhat.com/errata/RHSA-2026:26542, https://access.redhat.com/errata/RHSA-2026:27719, https://access.redhat.com/errata/RHSA-2026:27729, https://access.redhat.com/errata/RHSA-2026:28738, https://access.redhat.com/errata/RHSA-2026:28740, https://access.redhat.com/errata/RHSA-2026:28741, https://access.redhat.com/errata/RHSA-2026:28742, https://access.redhat.com/errata/RHSA-2026:28748, https://access.redhat.com/errata/RHSA-2026:28749, https://access.redhat.com/errata/RHSA-2026:28750, https://access.redhat.com/errata/RHSA-2026:28887, https://access.redhat.com/errata/RHSA-2026:28962, https://access.redhat.com/errata/RHSA-2026:33486, https://access.redhat.com/errata/RHSA-2026:34098, https://access.redhat.com/security/cve/CVE-2026-43037, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/43xxx/CVE-2026-43037.json, https://nvd.nist.gov/vuln/detail/CVE-2026-43037, https://bugzilla.redhat.com/show_bug.cgi?id=2464351, https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git