CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-43038

Critical · CVSS 9.8

Linux Kernel — Type Confusion (CWE-843) via IPv4/IPv6 control block overlap enabling out-of-bounds memory access in ICMPv6 error handling

CVSS
9.8
nvd
EPSS
0.26%
17th pct
KEV
No
Class
oss containerizable
NVD-CWE-noinfo, CWE-843

Description

In the Linux kernel, the following vulnerability has been resolved: ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach() Sashiko AI-review observed: In ip6_err_gen_icmpv6_unreach(), the skb is an outer IPv4 ICMP error packet where its cb contains an IPv4 inet_skb_parm. When skb is cloned into skb2 and passed to icmp6_send(), it uses IP6CB(skb2). IP6CB interprets the IPv4 inet_skb_parm as an inet6_skb_parm. The cipso offset in inet_skb_parm.opt directly overlaps with dsthao in inet6_skb_parm at offset 18. If an attacker sends a forged ICMPv4 error with a CIPSO IP option, dsthao would be a non-zero offset. Inside icmp6_send(), mip6_addr_swap() is called and uses ipv6_find_tlv(skb, opt->dsthao, IPV6_TLV_HAO). This would scan the inner, attacker-controlled IPv6 packet starting at that offset, potentially returning a fake TLV without checking if the remaining packet length can hold the full 18-byte struct ipv6_destopt_hao. Could mip6_addr_swap() then perform a 16-byte swap that extends past the end of the packet data into skb_shared_info? Should the cb array also be cleared in ip6_err_gen_icmpv6_unreach() and ip6ip6_err() to prevent this? This patch implements the first suggestion. I am not sure if ip6ip6_err() needs to be changed. A separate patch would be better anyway.

Search profile — drives PoC discovery

Symbols ip6_err_gen_icmpv6_unreachip6ip6_errIP6CBicmp6_sendmip6_addr_swapipv6_find_tlvinet_skb_parminet6_skb_parmipv6_destopt_haoIPV6_TLV_HAOdsthaoskb2->cbskb_shared_infoopt->dsthao
Keywords CVE-2026-43038ip6_err_gen_icmpv6_unreach cb clearLinux kernel IPv6 ICMP type confusioninet_skb_parm inet6_skb_parm overlapmip6_addr_swap out-of-boundsipv6_find_tlv fake TLVCIPSO IPv4 ICMPv6 unreachdsthao cipso offset overlapskb cb array ipv6 icmp exploitipv6 icmp CWE-843 Linux kernel PoC
Versions: Linux kernel versions prior to commits 0452b6526b2f, 1ceeebd5bd6d, 3d5127d998de, 86ab3e55673a, a2edbb6393972

Affected packages

Linux Kernel 3.13.0 → 5.10.253
Linux Kernel 5.11.0 → 5.15.203
Linux Kernel 5.16.0 → 6.1.168
Linux Kernel 6.13.0 → 6.18.22
Linux Kernel 6.19.0 → 6.19.12
Linux Kernel 6.2.0 → 6.6.134
Linux Kernel 6.7.0 → 6.12.81

References

Status: enriched · ingested 2026-07-14T18:00:20.000Z · profiled 2026-07-14T18:30:20.000Z