{"id":"CVE-2026-43038","summary":"ipv6: icmp: clear skb2-\u003ecb[] in ip6_err_gen_icmpv6_unreach()","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: icmp: clear skb2-\u003ecb[] in ip6_err_gen_icmpv6_unreach()\n\nSashiko AI-review observed:\n\n  In ip6_err_gen_icmpv6_unreach(), the skb is an outer IPv4 ICMP error packet\n  where its cb contains an IPv4 inet_skb_parm. When skb is cloned into skb2\n  and passed to icmp6_send(), it uses IP6CB(skb2).\n\n  IP6CB interprets the IPv4 inet_skb_parm as an inet6_skb_parm. The cipso\n  offset in inet_skb_parm.opt directly overlaps with dsthao in inet6_skb_parm\n  at offset 18.\n\n  If an attacker sends a forged ICMPv4 error with a CIPSO IP option, dsthao\n  would be a non-zero offset. Inside icmp6_send(), mip6_addr_swap() is called\n  and uses ipv6_find_tlv(skb, opt-\u003edsthao, IPV6_TLV_HAO).\n\n  This would scan the inner, attacker-controlled IPv6 packet starting at that\n  offset, potentially returning a fake TLV without checking if the remaining\n  packet length can hold the full 18-byte struct ipv6_destopt_hao.\n\n  Could mip6_addr_swap() then perform a 16-byte swap that extends past the end\n  of the packet data into skb_shared_info?\n\n  Should the cb array also be cleared in ip6_err_gen_icmpv6_unreach() and\n  ip6ip6_err() to prevent this?\n\nThis patch implements the first suggestion.\n\nI am not sure if ip6ip6_err() needs to be changed.\nA separate patch would be better anyway.","modified":"2026-09-09T03:30:29.928436257Z","published":"2026-05-01T14:15:35.986Z","related":["ALSA-2026:25120","ALSA-2026:25121","ALSA-2026:30129","ALSA-2026:30848","SUSE-SU-2026:21834-1","SUSE-SU-2026:21841-1","SUSE-SU-2026:21845-1","SUSE-SU-2026:21860-1","SUSE-SU-2026:21876-1","SUSE-SU-2026:21877-1","SUSE-SU-2026:21916-1","SUSE-SU-2026:21919-1","SUSE-SU-2026:2195-1","SUSE-SU-2026:2217-1","SUSE-SU-2026:2238-1","SUSE-SU-2026:22964-1","SUSE-SU-2026:22965-1","SUSE-SU-2026:22966-1","SUSE-SU-2026:22967-1","SUSE-SU-2026:22968-1","SUSE-SU-2026:22969-1","SUSE-SU-2026:22970-1","SUSE-SU-2026:22971-1","SUSE-SU-2026:22972-1","SUSE-SU-2026:22973-1","SUSE-SU-2026:22974-1","SUSE-SU-2026:22975-1","SUSE-SU-2026:22983-1","SUSE-SU-2026:22984-1","SUSE-SU-2026:22985-1","SUSE-SU-2026:22986-1","SUSE-SU-2026:22987-1","SUSE-SU-2026:22988-1","SUSE-SU-2026:22989-1","SUSE-SU-2026:22990-1","SUSE-SU-2026:22991-1","SUSE-SU-2026:22992-1","SUSE-SU-2026:22993-1","SUSE-SU-2026:22995-1","SUSE-SU-2026:23013-1","SUSE-SU-2026:23014-1","SUSE-SU-2026:23015-1","SUSE-SU-2026:23016-1","SUSE-SU-2026:23017-1","SUSE-SU-2026:23018-1","SUSE-SU-2026:23019-1","SUSE-SU-2026:23020-1","SUSE-SU-2026:23021-1","SUSE-SU-2026:23022-1","SUSE-SU-2026:23023-1","SUSE-SU-2026:23024-1","SUSE-SU-2026:23025-1","SUSE-SU-2026:23027-1","SUSE-SU-2026:23028-1","SUSE-SU-2026:23029-1","SUSE-SU-2026:23030-1","SUSE-SU-2026:23032-1","SUSE-SU-2026:23033-1","SUSE-SU-2026:23034-1","SUSE-SU-2026:23035-1","SUSE-SU-2026:23043-1","SUSE-SU-2026:23044-1","SUSE-SU-2026:23045-1","SUSE-SU-2026:23046-1","SUSE-SU-2026:23082-1","SUSE-SU-2026:23083-1","SUSE-SU-2026:23084-1","SUSE-SU-2026:23085-1","SUSE-SU-2026:23086-1","SUSE-SU-2026:23087-1","SUSE-SU-2026:23088-1","SUSE-SU-2026:23089-1","SUSE-SU-2026:23090-1","SUSE-SU-2026:23091-1","SUSE-SU-2026:23092-1","SUSE-SU-2026:23093-1","SUSE-SU-2026:23094-1","SUSE-SU-2026:23096-1","SUSE-SU-2026:23097-1","SUSE-SU-2026:23098-1","SUSE-SU-2026:23099-1","SUSE-SU-2026:23101-1","SUSE-SU-2026:23102-1","SUSE-SU-2026:23103-1","SUSE-SU-2026:23104-1","SUSE-SU-2026:23105-1","SUSE-SU-2026:23106-1","SUSE-SU-2026:23107-1","SUSE-SU-2026:23108-1","SUSE-SU-2026:2450-1","SUSE-SU-2026:2840-1","SUSE-SU-2026:2841-1","SUSE-SU-2026:3044-1","SUSE-SU-2026:3089-1","SUSE-SU-2026:3246-1","SUSE-SU-2026:3254-1","SUSE-SU-2026:3256-1","SUSE-SU-2026:3264-1","SUSE-SU-2026:3286-1","SUSE-SU-2026:3289-1","SUSE-SU-2026:3316-1","SUSE-SU-2026:3319-1","SUSE-SU-2026:3321-1","SUSE-SU-2026:3343-1","SUSE-SU-2026:3345-1","SUSE-SU-2026:3350-1","SUSE-SU-2026:3351-1","SUSE-SU-2026:3354-1","SUSE-SU-2026:3383-1","SUSE-SU-2026:3388-1","openSUSE-SU-2026:20826-1"],"database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/43xxx/CVE-2026-43038.json"},"references":[{"type":"WEB","url":"https://cert-portal.siemens.com/productcert/html/ssa-019113.html"},{"type":"WEB","url":"https://cert-portal.siemens.com/productcert/html/ssa-082556.html"},{"type":"WEB","url":"https://git.kernel.org/stable/c/0452b6526b2f54b2413b9cb4ff1ea2ac542c99c7"},{"type":"WEB","url":"https://git.kernel.org/stable/c/1ceeebd5bd6d855b17a5df625109bfe29129d7cf"},{"type":"WEB","url":"https://git.kernel.org/stable/c/3d5127d998de617b130aae96b138dba22ac6a8a7"},{"type":"WEB","url":"https://git.kernel.org/stable/c/86ab3e55673a7a49a841838776f1ab18d23a67b5"},{"type":"WEB","url":"https://git.kernel.org/stable/c/a2edbb6393972a02114b6003953a5cef3104fada"},{"type":"WEB","url":"https://git.kernel.org/stable/c/a4437faf135da293d16fcc4cc607316742bd0ebb"},{"type":"WEB","url":"https://git.kernel.org/stable/c/c438ba010171b70bad22fc18b1d5bdc3627476e8"},{"type":"WEB","url":"https://git.kernel.org/stable/c/e41953e7d118e2702bcb217879c173d9d1d3cd4e"},{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-43038.json"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:22900"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:22940"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:22964"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:23224"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:23237"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:24343"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:25120"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:25121"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:25533"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:26535"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:30129"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:30848"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:55618"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:55761"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:55762"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:55763"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:55837"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:56224"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:56225"},{"type":"ADVISORY","url":"https://access.redhat.com/security/cve/CVE-2026-43038"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/43xxx/CVE-2026-43038.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-43038"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2464397"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"ca15a078bd907df5fc1c009477869c5cbde3b753"},{"fixed":"c438ba010171b70bad22fc18b1d5bdc3627476e8"},{"fixed":"0452b6526b2f54b2413b9cb4ff1ea2ac542c99c7"},{"fixed":"a4437faf135da293d16fcc4cc607316742bd0ebb"},{"fixed":"3d5127d998de617b130aae96b138dba22ac6a8a7"},{"fixed":"e41953e7d118e2702bcb217879c173d9d1d3cd4e"},{"fixed":"a2edbb6393972a02114b6003953a5cef3104fada"},{"fixed":"1ceeebd5bd6d855b17a5df625109bfe29129d7cf"},{"fixed":"86ab3e55673a7a49a841838776f1ab18d23a67b5"}]}],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-43038.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.13.0"},{"fixed":"5.10.253"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.11.0"},{"fixed":"5.15.203"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.16.0"},{"fixed":"6.1.168"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.2.0"},{"fixed":"6.6.134"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.7.0"},{"fixed":"6.12.81"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.18.22"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"6.19.12"}]}],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-43038.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}