Junglewise Threat Intelligence

CVE-2026-43038: Linux Kernel type confusion in ip6_err_gen_icmpv6_unreach

CVE-2026-43038 · Severity: critical · CVSS 9.8 · Published 2026-05-01

Technologies: Red Hat Enterprise Linux 10.0, Linux Kernel. Vendors: Red Hat, Linux.

Executive brief

A vulnerability was identified in the Linux kernel's networking component that handles communication between different internet protocol versions (IPv4 and IPv6). An attacker could send specially crafted network packets to trigger a memory error, potentially allowing them to crash the system or gain unauthorized access. This affects systems acting as gateways or using specific tunneling protocols like SIT (IPv6 over IPv4).

Technical details

A type confusion vulnerability exists in the 'ip6_err_gen_icmpv6_unreach' function within the Linux kernel's IPv6 stack. When an IPv4 ICMP error packet is cloned to generate an ICMPv6 error, the control block (cb) remains populated with IPv4-specific data (inet_skb_parm). The IPv6 stack subsequently interprets this data as an IPv6 control block (inet6_skb_parm). Specifically, the 'cipso' offset from the IPv4 structure overlaps with the 'dsthao' offset in the IPv6 structure. An attacker can provide a forged ICMPv4 packet with a CIPSO option to manipulate the 'dsthao' offset, causing 'mip6_addr_swap' to perform a 16-byte swap at an attacker-controlled offset. This can result in out-of-bounds memory writes into 'skb_shared_info', leading to a system crash or arbitrary code execution. The fix involves zeroing the control block during the conversion process.

Affected products

  • Linux Linux Kernel All versions prior to the April 2026 patches
  • Red Hat Enterprise Linux 10.0
  • Red Hat Enterprise Linux 9.2

Timeline

  • 2026-03-26: disclosed: Initial patch submission by Eric Dumazet
  • 2026-04-18: patched: Patch committed to stable tree
  • 2026-05-01: advisory: CVE-2026-43038 published

References

Related threats