Description
In the Linux kernel, the following vulnerability has been resolved:

ip6_tunnel: clear skb2->cb[] in ip4ip6_err()

Oskar Kjos reported the following problem.

ip4ip6_err() calls icmp_send() on a cloned skb whose cb[] was written
by the IPv6 receive path as struct inet6_skb_parm. icmp_send() passes
IPCB(skb2) to __ip_options_echo(), which interprets that cb[] region
as struct inet_skb_parm (IPv4). The layouts differ: inet6_skb_parm.nhoff
at offset 14 overlaps inet_skb_parm.opt.rr, producing a non-zero rr
value. __ip_options_echo() then reads optlen from attacker-controlled
packet data at sptr[rr+1] and copies that many bytes into dopt->__data,
a fixed 40-byte stack buffer (IP_OPTIONS_DATA_FIXED_SIZE).

To fix this we clear skb2->cb[], as suggested by Oskar Kjos.

Also add minimal IPv4 header validation (version == 4, ihl >= 5).
Published: 2026-05-01
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4561-1 linux-6.1 security update
Debian DLA Debian DLA DLA-4606-1 linux security update
Debian DSA Debian DSA DSA-6243-1 linux security update
Ubuntu USN Ubuntu USN USN-8490-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8491-1 Linux kernel (OEM) vulnerabilities
Ubuntu USN Ubuntu USN USN-8492-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8493-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8492-2 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8493-2 Linux kernel (Oracle) vulnerabilities
Ubuntu USN Ubuntu USN USN-8497-1 Linux kernel (Low Latency) vulnerabilities
Ubuntu USN Ubuntu USN USN-8498-1 Linux kernel (NVIDIA Tegra) vulnerabilities
Ubuntu USN Ubuntu USN USN-8499-1 Linux kernel (Xilinx) vulnerabilities
Ubuntu USN Ubuntu USN USN-8501-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8508-1 Linux kernel (NVIDIA) vulnerabilities
Ubuntu USN Ubuntu USN USN-8492-3 Linux kernel (Raspberry Pi Real-time) vulnerabilities
Ubuntu USN Ubuntu USN USN-8490-2 Linux kernel (Real-time) vulnerabilities
Ubuntu USN Ubuntu USN USN-8492-4 Linux kernel (Raspberry Pi) vulnerabilities
Ubuntu USN Ubuntu USN USN-8492-5 Linux kernel (FIPS) vulnerabilities
Ubuntu USN Ubuntu USN USN-8527-1 Linux kernel (Raspberry Pi) vulnerabilities
Ubuntu USN Ubuntu USN USN-8528-1 Linux kernel (Xilinx ZynqMP) vulnerabilities
Ubuntu USN Ubuntu USN USN-8529-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8530-1 Linux kernel (AWS) vulnerabilities
Ubuntu USN Ubuntu USN USN-8545-1 Linux kernel (HWE) vulnerabilities
Ubuntu USN Ubuntu USN USN-8546-1 Linux kernel (Raspberry Pi) vulnerabilities
Ubuntu USN Ubuntu USN USN-8547-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8548-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8604-1 Linux kernel (Azure) vulnerabilities
Ubuntu USN Ubuntu USN USN-8605-1 Linux kernel (Azure CVM) vulnerabilities
Ubuntu USN Ubuntu USN USN-8606-1 Linux kernel (Azure) vulnerabilities
Ubuntu USN Ubuntu USN USN-8607-1 Linux kernel (Azure CVM) vulnerabilities
Ubuntu USN Ubuntu USN USN-8609-1 Linux kernel (Azure CVM) vulnerabilities
Ubuntu USN Ubuntu USN USN-8547-2 Linux kernel (Azure FIPS) vulnerabilities
Ubuntu USN Ubuntu USN USN-8615-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8616-1 Linux kernel (IBM) vulnerabilities
Ubuntu USN Ubuntu USN USN-8619-1 Linux kernel (HWE) vulnerabilities
Ubuntu USN Ubuntu USN USN-8615-2 Linux kernel (Raspberry Pi) vulnerabilities
References
Link Providers
https://access.redhat.com/errata/RHSA-2026:22900 cve-icon
https://access.redhat.com/errata/RHSA-2026:22940 cve-icon
https://access.redhat.com/errata/RHSA-2026:22964 cve-icon
https://access.redhat.com/errata/RHSA-2026:23224 cve-icon
https://access.redhat.com/errata/RHSA-2026:23237 cve-icon
https://access.redhat.com/errata/RHSA-2026:24343 cve-icon
https://access.redhat.com/errata/RHSA-2026:25044 cve-icon
https://access.redhat.com/errata/RHSA-2026:25120 cve-icon
https://access.redhat.com/errata/RHSA-2026:25121 cve-icon
https://access.redhat.com/errata/RHSA-2026:25181 cve-icon
https://access.redhat.com/errata/RHSA-2026:25186 cve-icon
https://access.redhat.com/errata/RHSA-2026:25191 cve-icon
https://access.redhat.com/errata/RHSA-2026:25193 cve-icon
https://access.redhat.com/errata/RHSA-2026:25200 cve-icon
https://access.redhat.com/errata/RHSA-2026:25217 cve-icon
https://access.redhat.com/errata/RHSA-2026:25533 cve-icon
https://access.redhat.com/errata/RHSA-2026:25534 cve-icon
https://access.redhat.com/errata/RHSA-2026:26528 cve-icon
https://access.redhat.com/errata/RHSA-2026:26535 cve-icon
https://access.redhat.com/errata/RHSA-2026:26542 cve-icon
https://access.redhat.com/errata/RHSA-2026:27719 cve-icon
https://access.redhat.com/errata/RHSA-2026:27729 cve-icon
https://access.redhat.com/errata/RHSA-2026:28738 cve-icon
https://access.redhat.com/errata/RHSA-2026:28740 cve-icon
https://access.redhat.com/errata/RHSA-2026:28741 cve-icon
https://access.redhat.com/errata/RHSA-2026:28742 cve-icon
https://access.redhat.com/errata/RHSA-2026:28748 cve-icon
https://access.redhat.com/errata/RHSA-2026:28749 cve-icon
https://access.redhat.com/errata/RHSA-2026:28750 cve-icon
https://access.redhat.com/errata/RHSA-2026:28887 cve-icon
https://access.redhat.com/errata/RHSA-2026:28962 cve-icon
https://access.redhat.com/errata/RHSA-2026:33486 cve-icon
https://access.redhat.com/errata/RHSA-2026:34098 cve-icon
https://access.redhat.com/errata/RHSA-2026:41236 cve-icon
https://access.redhat.com/errata/RHSA-2026:44232 cve-icon
https://access.redhat.com/security/cve/CVE-2026-43037 cve-icon
https://bugzilla.redhat.com/show_bug.cgi?id=2464351 cve-icon
https://git.kernel.org/stable/c/1063515ce15ff31065c4e7f8265f4c2fd3c54876 cve-icon cve-icon
https://git.kernel.org/stable/c/2cc6e3b0fe0f0242d1f530a93a4924f48ab85ba5 cve-icon cve-icon
https://git.kernel.org/stable/c/2edfa31769a4add828a7e604b21cb82aaaa05925 cve-icon cve-icon
https://git.kernel.org/stable/c/4a622658f384b03560834cbe8ffcfe69a278f7c8 cve-icon cve-icon
https://git.kernel.org/stable/c/590f622669b97eaf7b57a1de7b0a6e68c5d8b2c3 cve-icon cve-icon
https://git.kernel.org/stable/c/a0c4ce9900a108eaf55d0f3b399cb55999647d39 cve-icon cve-icon
https://git.kernel.org/stable/c/d6621f60192fe10c047a4487be42a6f4c150707f cve-icon cve-icon
https://git.kernel.org/stable/c/ea9f65b27c8404e164848ebff1443310fd187629 cve-icon cve-icon
https://lore.kernel.org/linux-cve-announce/2026050102-CVE-2026-43037-0346@gregkh/T cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2026-43037 cve-icon
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-43037.json cve-icon
https://www.cve.org/CVERecord?id=CVE-2026-43037 cve-icon
History

Wed, 12 Aug 2026 12:30:00 +0000

Type Values Removed Values Added
References

Mon, 04 May 2026 20:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119

Mon, 04 May 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-787
CPEs cpe:2.3:o:linux:linux_kernel:7.0:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc5:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc6:*:*:*:*:*:*

Sun, 03 May 2026 06:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.0, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Sat, 02 May 2026 12:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119

Sat, 02 May 2026 10:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-120

Sat, 02 May 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.0, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}

threat_severity

Important


Fri, 01 May 2026 23:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-120

Fri, 01 May 2026 14:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() Oskar Kjos reported the following problem. ip4ip6_err() calls icmp_send() on a cloned skb whose cb[] was written by the IPv6 receive path as struct inet6_skb_parm. icmp_send() passes IPCB(skb2) to __ip_options_echo(), which interprets that cb[] region as struct inet_skb_parm (IPv4). The layouts differ: inet6_skb_parm.nhoff at offset 14 overlaps inet_skb_parm.opt.rr, producing a non-zero rr value. __ip_options_echo() then reads optlen from attacker-controlled packet data at sptr[rr+1] and copies that many bytes into dopt->__data, a fixed 40-byte stack buffer (IP_OPTIONS_DATA_FIXED_SIZE). To fix this we clear skb2->cb[], as suggested by Oskar Kjos. Also add minimal IPv4 header validation (version == 4, ihl >= 5).
Title ip6_tunnel: clear skb2->cb[] in ip4ip6_err()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-08-12T12:04:46.644Z

Reserved: 2026-05-01T14:12:55.978Z

Link: CVE-2026-43037

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2026-05-01T15:16:48.383

Modified: 2026-08-12T12:19:19.617

Link: CVE-2026-43037

cve-icon Redhat

Severity : Important

Publid Date: 2026-05-01T00:00:00Z

Links: CVE-2026-43037 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-05-04T21:30:09Z

Weaknesses