Executive brief
A vulnerability exists in the Linux kernel's networking subsystem, specifically within the Netfilter component used for firewalling and packet filtering. An attacker could send specially crafted network packets to trigger an out-of-bounds memory read. This could lead to system instability, service outages, or the potential exposure of sensitive information from the system's memory.
Technical details
An out-of-bounds read vulnerability (CWE-125) exists in net/netfilter/xt_tcpmss.c within the Linux kernel. The TCP option parser fails to validate the remaining length of the option field before attempting to read the option length (optlen) at index op[i+1]. If a packet contains a trailing byte that is not an End of Option List (EOL) or No-Operation (NOP), the code indexes beyond the allocated buffer. This can occur when i + 1 equals the total option length, leading to a read beyond the stack buffer or into subsequent packet payload. This can be exploited by a remote attacker to cause a denial of service or potentially leak kernel memory. Patches have been released across multiple stable kernel branches.
Affected products
- Linux Linux Kernel 2.6.12.1 to 5.10.252, 5.11 to 5.15.202, 5.16 to 6.1.165, 6.2 to 6.6.128, 6.7 to 6.12.75, 6.13 to 6.18.16, 6.19 to 6.19.6
Timeline
- 2026-01-19: other: Vulnerability fix authored
- 2026-05-06: disclosed: Initial publication of CVE-2026-43190
- 2026-05-06: advisory
References
- https://git.kernel.org/stable/c/07a9b32eaae792ff7d0fcac14d8920c937c0a9c3
- https://git.kernel.org/stable/c/5e13d0a37666955b6cfddc0f73cb40ed645b8a05
- https://git.kernel.org/stable/c/735ee8582da3d239eb0c7a53adca61b79fb228b3
- https://git.kernel.org/stable/c/8b300f726640c48c3edfe9c453334dd801f4b74e
- https://git.kernel.org/stable/c/cd5beda7e0e32865e214f28034bb92c1cecff885
- https://git.kernel.org/stable/c/eaedc0bc18be46fe7f58170e967959a932c4f824
- https://git.kernel.org/stable/c/f6c412dcfd76b0516d51aa847d8f4c7b70381b09