CVE-2026-43083

Updated on 06 May 2026

Severity

9.1 Critical severity

Details

CVSS score
9.1

Overview

About vulnerability

In the Linux kernel, the following vulnerability has been resolved: net: ioam6: fix OOB and missing lock When trace->type.bit6 is set: if (trace->type.bit6) { … queue = skb_get_tx_queue(dev, skb); qdisc = rcu_dereference(queue->qdisc); This code can lead to an out-of-bounds access of the dev->_tx[] array when is_input is true. In such a case, the packet is on the RX path and skb->queue_mapping contains the RX queue index of the ingress device. If the ingress device has more RX queues than the egress device (dev) has TX queues, skb_get_queue_mapping(skb) will exceed dev->num_tx_queues. Add a check to avoid this situation since skb_get_tx_queue() does not clamp the index. This issue has also revealed that per queue visibility cannot be accurate and will be replaced later as a new feature. While at it, add missing lock around qdisc_qstats_qlen_backlog(). The function __ioam6_fill_trace_data() is called from both softirq and process contexts, hence the use of spin_lock_bh() here. A flaw was found in the Linux kernel’s ioam6 network module. A remote attacker could potentially trigger an out-of-bounds access in the skb_get_tx_queue function by sending specially crafted network packets. This occurs when an ingress device has more receive queues than the egress device has transmit queues, which can lead to a system crash, resulting in a Denial of Service (DoS). Furthermore, a missing lock around the qdisc_qstats_qlen_backlog function introduces a race condition, potentially causing data corruption or system instability.

Details

KernelCare state

Live-patch status from KernelCare for each operating system.

Operating system Status Covered kernels
Amazon Linux 2023 Planned