CVE-2026-43186 Details
Description
In the Linux kernel, the following vulnerability has been resolved: ipv6: ioam: fix heap buffer overflow in __ioam6_fill_trace_data() On the receive path, __ioam6_fill_trace_data() uses trace->nodelen to decide how much data to write for each node. It trusts this field as-is from the incoming packet, with no consistency check against trace->type (the 24-bit field that tells which data items are present). A crafted packet can set nodelen=0 while setting type bits 0-21, causing the function to write ~100 bytes past the allocated region (into skb_shared_info), which corrupts adjacent heap memory and leads to a kernel panic. Add a shared helper ioam6_trace_compute_nodelen() in ioam6.c to derive the expected nodelen from the type field, and use it: - in ioam6_iptunnel.c (send path, existing validation) to replace the open-coded computation; - in exthdrs.c (receive path, ipv6_hop_ioam) to drop packets whose nodelen is inconsistent with the type field, before any data is written. Per RFC 9197, bits 12-21 are each short (4-octet) fields, so they are included in IOAM6_MASK_SHORT_FIELDS (changed from 0xff100000 to 0xff1ffc00).
A heap buffer overflow vulnerability has been identified in the Linux kernel's IOAM6 (In-situ Operations, Administration, and Maintenance) implementation for IPv6. This issue arises in the function '__ioam6_fill_trace_data()' when processing incoming packets. The function relies on the 'nodelen' field of the trace header to determine how much data to write, but it does not validate this field against the 'type' field, which indicates which data items are present. An attacker can craft a packet that sets 'nodelen' to zero while manipulating the type bits, causing the function to write approximately 100 bytes beyond the allocated buffer into shared kernel memory. This memory corruption leads to a kernel panic.
The vulnerability has been addressed by adding a consistency check for the 'nodelen' field in relation to the 'type' field, ensuring that only valid data lengths are processed. Users should upgrade to the latest stable version of the Linux kernel where this fix has been applied.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/0591d6509c2ff13f09ea2998434aba0c0472e978 | kernel.org | Patch |
| https://git.kernel.org/stable/c/632d233cf2e64a46865ae2c064ae3c9df7c8864f | kernel.org | Patch |
| https://git.kernel.org/stable/c/6db8b56eed62baacaf37486e83378a72635c04cc | kernel.org | Patch |
| https://git.kernel.org/stable/c/e90346a2f1e8917d5760a44a1f61c44e3b36d96b | kernel.org | Patch |
| https://git.kernel.org/stable/c/ea3632aefc04205436868541638e26f4a74d5637 | kernel.org | Patch |
| https://git.kernel.org/stable/c/f4d9d4b8fd839719d564651671e24c62c545c23b | kernel.org | Patch |
| https://git.kernel.org/stable/c/fb3c662fafebc5b9d74417ed1de8759f6bb72143 | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-787 | Out-of-bounds Write | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 5.15, < 5.15.202 >= 5.16, < 6.1.165 >= 6.2, < 6.6.128 >= 6.7, < 6.12.75 >= 6.13, < 6.18.16 >= 6.19, < 6.19.6 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | kernel.org |
| May 11, 2026 | Initial Analysis | [email protected] |
| May 8, 2026 | CVE Modified | kernel.org |
| May 6, 2026 | New CVE Received | kernel.org |