Heap-based buffer overflow in Linux kernel - CVE-2026-43186

 

Heap-based buffer overflow in Linux kernel - CVE-2026-43186

Published: May 7, 2026


Vulnerability identifier: #VU130546
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-43186
CWE-ID: CWE-122
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to a heap-based buffer overflow in __ioam6_fill_trace_data() when processing a crafted incoming IPv6 IOAM packet on the receive path. A remote attacker can send a specially crafted packet to cause a denial of service.

A packet with an inconsistent nodelen field and type bits can trigger an out-of-bounds write of about 100 bytes into adjacent heap memory.


Affected software

Linux kernel
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Ubuntu
openEuler
linux (Ubuntu package)
linux-xilinx-zynqmp (Ubuntu package)
linux-raspi (Ubuntu package)
linux-gcp-5.15 (Ubuntu package)
linux-oracle-5.15 (Ubuntu package)
linux-azure-fips (Ubuntu package)
kernel-headers
python3-perf
python3-perf-debuginfo
perf-debuginfo
perf
kernel-tools-devel
kernel-tools-debuginfo
kernel-tools
kernel-source
kernel-devel
kernel-debugsource
kernel-debuginfo
bpftool-debuginfo
bpftool
kernel
kernel-extra-modules
linux-hwe-6.8 (Ubuntu package)
linux-nvidia-tegra (Ubuntu package)
linux-aws-6.8 (Ubuntu package)
linux-azure-fde (Ubuntu package)
linux-azure-fde-6.8 (Ubuntu package)
linux-azure (Ubuntu package)
linux-raspi-realtime (Ubuntu package)
kernel (Red Hat package)
linux-hwe-6.17 (Ubuntu package)
linux-azure-fde-6.17 (Ubuntu package)
linux-azure-6.17 (Ubuntu package)
linux-nvidia-6.17 (Ubuntu package)
linux-oem-6.17 (Ubuntu package)

How to mitigate CVE-2026-43186

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3
linux (Ubuntu package) - addressed in versions 5.15.0.183.154, 5.15.0-183.193, 5.15.0-183.193~20.04.1, 5.15.0.185.108, 5.15.0.185.166, 5.15.0-185.195+fips1, 5.15.0-185.195~20.04.1, 5.15.0-1052.52, 5.15.0.1052.54, 5.15.0-1063.63, 5.15.0-1063.63~20.04.1, 5.15.0.1094.93, 5.15.0-1094.102, 5.15.0.1103.99, 5.15.0-1103.105, 5.15.0.1103.107, 5.15.0-1103.108, 5.15.0.1105.102, 5.15.0.1105.109, 5.15.0-1105.109~20.04.1, 5.15.0.1106.105, 5.15.0.1106.106, 5.15.0-1106.107, 5.15.0-1106.112, 5.15.0.1107.106, 5.15.0-1107.113, 5.15.0.1108.104, 5.15.0-1108.114, 5.15.0.1110.114, 5.15.0-1110.119, 5.15.0.1111.101, 5.15.0.1111.107, 5.15.0.1111.108, 5.15.0.1111.114, 5.15.0-1111.118, 5.15.0-1111.118+fips1, 5.15.0-1111.118~20.04.1, 5.15.0-1111.121, 5.15.0-1111.121+fips1, 5.15.0.1116.114, 5.15.0-1116.125, 5.15.0-1116.125~20.04.1, 6.8.0-134.134, 6.8.0-1057.58~22.04.1, 6.8.0-1058.61+fips1, 6.8.0-1058.61~22.04.1, 6.8.0-1060.61, 6.8.0-1060.63+fips1, 6.8.0-1060.63~22.04.1, 6.8.0-1063.69, 6.8.0-1063.69+fips1, 6.8.1-1055.56, 6.8.1-1055.56~22.04.1, 6.17.0-40.40
linux-xilinx-zynqmp (Ubuntu package) - addressed in versions 5.15.0.1074.77, 5.15.0-1074.78
linux-raspi (Ubuntu package) - addressed in versions 5.15.0.1105.103, 5.15.0-1105.108, 6.8.0-1060.64, 6.17.0-1021.21
linux-gcp-5.15 (Ubuntu package) - addressed in versions 5.15.0-1106.112~20.04.1, 5.15.0-1111.121~20.04.1
linux-oracle-5.15 (Ubuntu package) - update to 5.15.0-1108.114~20.04.1
linux-azure-fips (Ubuntu package) - addressed in versions 5.15.0.1116.101, 5.15.0-1116.125+fips1, 6.8.0-134.134+fips1, 6.8.0-1062.69+fips1
kernel-headers - addressed in versions 6.6.0-145.1.19.156, 6.6.0-145.3.14.145
python3-perf - addressed in versions 6.6.0-145.1.19.156, 6.6.0-145.3.14.145
python3-perf-debuginfo - addressed in versions 6.6.0-145.1.19.156, 6.6.0-145.3.14.145
perf-debuginfo - addressed in versions 6.6.0-145.1.19.156, 6.6.0-145.3.14.145
perf - addressed in versions 6.6.0-145.1.19.156, 6.6.0-145.3.14.145
kernel-tools-devel - addressed in versions 6.6.0-145.1.19.156, 6.6.0-145.3.14.145
kernel-tools-debuginfo - addressed in versions 6.6.0-145.1.19.156, 6.6.0-145.3.14.145
kernel-tools - addressed in versions 6.6.0-145.1.19.156, 6.6.0-145.3.14.145
kernel-source - addressed in versions 6.6.0-145.1.19.156, 6.6.0-145.3.14.145
kernel-devel - addressed in versions 6.6.0-145.1.19.156, 6.6.0-145.3.14.145
kernel-debugsource - addressed in versions 6.6.0-145.1.19.156, 6.6.0-145.3.14.145
kernel-debuginfo - addressed in versions 6.6.0-145.1.19.156, 6.6.0-145.3.14.145
bpftool-debuginfo - addressed in versions 6.6.0-145.1.19.156, 6.6.0-145.3.14.145
bpftool - addressed in versions 6.6.0-145.1.19.156, 6.6.0-145.3.14.145
kernel - addressed in versions 6.6.0-145.1.19.156, 6.6.0-145.3.14.145
kernel-extra-modules - update to 6.6.0-145.3.14.145
linux-hwe-6.8 (Ubuntu package) - update to 6.8.0-136.136~22.04.1
linux-nvidia-tegra (Ubuntu package) - update to 6.8.0-1029.30
linux-aws-6.8 (Ubuntu package) - addressed in versions 6.8.0-1045.48, 6.8.0-1057.58~22.04.1, 6.8.0-1058.61.1, 6.8.0-1058.64, 6.8.0-1060.61~22.04.1, 6.8.0-1060.63~22.04.1, 6.8.0-1063.69~22.04.1
linux-azure-fde (Ubuntu package) - update to 6.8.0-1062.69
linux-azure-fde-6.8 (Ubuntu package) - update to 6.8.0-1062.69~22.04.1
linux-azure (Ubuntu package) - addressed in versions 6.8.0-1063.71, 6.8.0-1063.71~22.04.1
linux-raspi-realtime (Ubuntu package) - update to 6.8.0-2049.50
kernel (Red Hat package) - update to 6.12.0-211.44.1.el10_2
linux-hwe-6.17 (Ubuntu package) - update to 6.17.0-40.40~24.04.1
linux-azure-fde-6.17 (Ubuntu package) - update to 6.17.0-1018.18~24.04.1
linux-azure-6.17 (Ubuntu package) - update to 6.17.0-1021.21~24.04.1
linux-nvidia-6.17 (Ubuntu package) - update to 6.17.0-1026.26
linux-oem-6.17 (Ubuntu package) - update to 6.17.0-1028.28

External References

Related Security Bulletins