Executive brief
A vulnerability in the Linux kernel's networking subsystem can cause network connections to become permanently stuck or "stalled." This occurs when the system incorrectly handles errors during the transmission of large data packets, leading to a mismatch between what the sender and receiver believe has been delivered. This can result in a denial of service for specific network applications or services running on the affected system.
Technical details
A logic error exists in the Linux kernel's handling of transmit (xmit) return codes for GSO frames, specifically when using virtual devices (veth) without a Qdisc. When a GSO super frame is segmented, the loss of a single segment can cause the entire GSO frame to be reported as failed to the TCP layer. This prevents the sender from advancing its 'snd_nxt' sequence number even though subsequent segments were successfully received. When the receiver ACKs the successfully received segments, the sender rejects the ACK as 'TCP_ACK_UNSENT_DATA', resulting in a permanent connection stall. The fix involves masking GSO transmission errors in Qdisc-less paths to ensure the TCP state remains consistent.
Affected products
- Linux Linux Kernel 3.18 to 5.10.252, 5.11 to 5.15.202, 5.16 to 6.1.165, 6.2 to 6.6.128, 6.7 to 6.12.75, 6.13 to 6.18.16, 6.19 to 6.19.6
Timeline
- 2026-02-23: patched: Initial patch by Jakub Kicinski
- 2026-05-06: disclosed: CVE-2026-43194 published
References
- https://git.kernel.org/stable/c/0c9de092ef8c50a7ee9612811566f0aa81d8d7b6
- https://git.kernel.org/stable/c/4cb163e9efcac4cd35c3043e097f25081a5c015c
- https://git.kernel.org/stable/c/56bd32c0edca34041a5c215887fcf562fae2e2db
- https://git.kernel.org/stable/c/7aa767d0d3d04e50ae94e770db7db8197f666970
- https://git.kernel.org/stable/c/9ac6aebef4b4bfc5ed408b0b65645981574bc780
- https://git.kernel.org/stable/c/ae3f627b45fbc3c776a4e484696f3cad7cbb4eca
- https://git.kernel.org/stable/c/c86901d22c89a6bf4e2f013e948aaabc60869893