SB2026050208 - Always-Incorrect Control Flow Implementation in Linux kernel core
Published: May 2, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Always-Incorrect Control Flow Implementation (CVE-ID: CVE-2026-43057)
CWE-ID: CWE-670 - Always-Incorrect Control Flow Implementation
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper handling of checksum offload fallback in the IPv6 GSO fallback logic when processing tunneled IPv6 traffic with extension headers or without an inner IP protocol. A local user can send specially crafted packets to cause a denial of service.
The issue affects tunneled traffic, including cases where the inner header rather than the outer network header must be validated.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/2094a7cf91b71367b649f991aacc7b579f793d0b
- https://git.kernel.org/stable/c/33670f780e0120c3dacda188c512bbffe0b6044c
- https://git.kernel.org/stable/c/732fdeb2987c94b439d51f5cb9addddc2fc48c42
- https://git.kernel.org/stable/c/a98b78116a27e2a57b696b569b2cb431c95cf9b6
- https://git.kernel.org/stable/c/c4336a07eb6b2526dc2b62928b5104b41a7f81f5
- https://git.kernel.org/stable/c/ed71cf465c75f5688b07a35d373cd1d6b589c8ea