CVE-2026-43190 Details
Description
In the Linux kernel, the following vulnerability has been resolved: netfilter: xt_tcpmss: check remaining length before reading optlen Quoting reporter: In net/netfilter/xt_tcpmss.c (lines 53-68), the TCP option parser reads op[i+1] directly without validating the remaining option length. If the last byte of the option field is not EOL/NOP (0/1), the code attempts to index op[i+1]. In the case where i + 1 == optlen, this causes an out-of-bounds read, accessing memory past the optlen boundary (either reading beyond the stack buffer _opt or the following payload).
A vulnerability exists in the Linux kernel's netfilter component, specifically within the TCP MSS (Maximum Segment Size) option parser. The issue arises because the parser reads TCP options without first validating the remaining length of the option field. If the last byte is not an End of Option List (EOL) or No Operation (NOP), the parser may attempt to access memory beyond the intended limit, leading to an out-of-bounds read. This could potentially allow for unauthorized memory access, either by reading past the end of a stack buffer or into adjacent payload data.
Users can upgrade to the latest version of the Linux kernel where this vulnerability has been patched. The specific commit that addresses this issue is available in the Linux kernel stable tree.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/07a9b32eaae792ff7d0fcac14d8920c937c0a9c3 | kernel.org | Patch |
| https://git.kernel.org/stable/c/5e13d0a37666955b6cfddc0f73cb40ed645b8a05 | kernel.org | Patch |
| https://git.kernel.org/stable/c/735ee8582da3d239eb0c7a53adca61b79fb228b3 | kernel.org | Patch |
| https://git.kernel.org/stable/c/8b300f726640c48c3edfe9c453334dd801f4b74e | kernel.org | Patch |
| https://git.kernel.org/stable/c/cd5beda7e0e32865e214f28034bb92c1cecff885 | kernel.org | Patch |
| https://git.kernel.org/stable/c/eaedc0bc18be46fe7f58170e967959a932c4f824 | kernel.org | Patch |
| https://git.kernel.org/stable/c/f6c412dcfd76b0516d51aa847d8f4c7b70381b09 | kernel.org | Patch |
| https://git.kernel.org/stable/c/f895191dc32c53eaf443b6443fe40945b2f92287 | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-125 | Out-of-bounds Read | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 2.6.12.1, < 5.10.252 >= 5.11, < 5.15.202 >= 5.16, < 6.1.165 >= 6.2, < 6.6.128 >= 6.7, < 6.12.75 >= 6.13, < 6.18.16 >= 6.19, < 6.19.6 2.6.12 - 2.6.12 rc2 2.6.12 rc3 2.6.12 rc4 2.6.12 rc5 2.6.12 rc6 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | kernel.org |
| May 11, 2026 | Initial Analysis | [email protected] |
| May 8, 2026 | CVE Modified | kernel.org |
| May 6, 2026 | New CVE Received | kernel.org |