Executive brief
A race condition vulnerability was identified in the Linux kernel's networking stack, specifically affecting how it handles certain IPv6 network connections. The Linux kernel is the core software that manages computer hardware and system resources. An attacker could potentially exploit this flaw to cause system instability or unauthorized access to data by timing network requests in a specific way.
Technical details
A race condition exists in tcp_v6_syn_recv_sock() within the Linux kernel's networking stack. The vulnerability occurs because the child socket becomes visible in the TCP ehash table before its IPv6 protocol information (pinet6) is correctly initialized, leaving it pointing to the listener's information while other CPUs may already be accessing it. This improper synchronization can lead to use-after-free or other memory corruption scenarios. The fix involves moving the initialization logic into a new helper, tcp_v6_mapped_child_init(), and ensuring it is called before the socket is inserted into the ehash table. This issue was discovered by syzbot and affects kernels dating back to version 2.6.12-rc2.
Affected products
- Linux Linux Kernel 2.6.12-rc2 and later
Timeline
- 2026-02-17: disclosed: Vulnerability reported and patch authored by Eric Dumazet
- 2026-03-04: patched: Patch committed to stable tree
- 2026-05-06: advisory: CVE-2026-43198 published
References
- https://git.kernel.org/stable/c/7178e2a8027423b2af17ab95df73a749a5b72e5b
- https://git.kernel.org/stable/c/858d2a4f67ff69e645a43487ef7ea7f28f06deae
- https://git.kernel.org/stable/c/fe89b2f05b854847784f91127319172945c1fadd
- https://access.redhat.com/errata/RHSA-2026:30129
- https://access.redhat.com/errata/RHSA-2026:33215
- https://access.redhat.com/errata/RHSA-2026:33285
- https://access.redhat.com/security/cve/CVE-2026-43198