Memory corruption in Linux kernel - CVE-2026-43329
Published: May 9, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper restriction of operations within the bounds of a memory buffer in flowtable hardware offload action handling when processing IPv6 flowtable offload configurations with multiple actions. A remote attacker can trigger a flow configuration that exceeds the supported number of actions to cause a denial of service.
The issue can be reached in IPv6 setups involving combinations of ethernet mangling, NAT, double VLAN for QinQ, redirect, and tunnel-related actions.
How to mitigate CVE-2026-43329
Sources
- https://git.kernel.org/stable/c/504c9456699dcf4d15195ef34a0fa94a80bfc877
- https://git.kernel.org/stable/c/5382bb03e9c33b089d60788478b922a2dca284cc
- https://git.kernel.org/stable/c/57c78bd2e2dd08897acd35b2bf8bcef322e36f5e
- https://git.kernel.org/stable/c/76522fcdbc3a02b568f5d957f7e66fc194abb893
- https://git.kernel.org/stable/c/879959a7a2be814dd57568655eafa3d8f4d0309e
- https://git.kernel.org/stable/c/ead66c77303f760f6c30be96e2e20d5a77cef614
- https://git.kernel.org/stable/c/fe9018d3e94329f1951b00805a8640bc06f56ead