Recently, an out-of-bounds read vulnerability (CVE-2026-43190) has been disclosed in the Linux kernel netfilter xt_tcpmss module. The TCP option parser reads op[i+1] without validating the remaining length. When the last option byte is not EOL(0) or NOP(1) and i + 1 == optlen, the code reads past the optlen boundary, causing an out-of-bounds read. A remote attacker can trigger this by sending crafted TCP packets, leading to information disclosure or denial of service.
Linux kernel is the core component of Linux operating systems. Check your system and implement timely security hardening.
Reference:
https://nvd.nist.gov/vuln/detail/CVE-2026-43190
https://lore.kernel.org/linux-cve-announce/2026050642-CVE-2026-43190-f1c9@gregkh/
important
(Severity: low, medium, important, and critical)
2.6.12 <= Linux kernel < 5.10.252
5.11 <= Linux kernel < 5.15.202
5.16 <= Linux kernel < 6.1.165
6.2 <= Linux kernel < 6.6.128
6.7 <= Linux kernel < 6.12.75
6.13 <= Linux kernel < 6.18.16
6.19 <= Linux kernel < 6.19.6
All Linux-based system distributions running an affected kernel version are impacted, including but not limited to Ubuntu, Red Hat Enterprise Linux, Oracle Linux, SUSE, Amazon Linux, and other embedded/custom systems.
Linux Kernel 5.10 >= 5.10.252 (commit f895191dc32c)
Linux Kernel 5.15 >= 5.15.202 (commit cd5beda7e0e3)
Linux Kernel 6.1 >= 6.1.165 (commit eaedc0bc18be)
Linux Kernel 6.6 >= 6.6.128 (commit 07a9b32eaae7)
Linux Kernel 6.12 >= 6.12.75 (commit 8b300f726640)
Linux Kernel 6.18 >= 6.18.16 (commit 5e13d0a37666)
Linux Kernel 6.19 >= 6.19.6 (commit f6c412dcfd76)
Linux Kernel 7.0 (commit 735ee8582da3)
This vulnerability has been fixed in later official versions. If your service version falls into the affected range, upgrade it to a latest secure version.
https://git.kernel.org/stable/c/f895191dc32c53eaf443b6443fe40945b2f92287
https://git.kernel.org/stable/c/cd5beda7e0e32865e214f28034bb92c1cecff885
https://git.kernel.org/stable/c/eaedc0bc18be46fe7f58170e967959a932c4f824
https://git.kernel.org/stable/c/07a9b32eaae792ff7d0fcac14d8920c937c0a9c3
https://git.kernel.org/stable/c/8b300f726640c48c3edfe9c453334dd801f4b74e
https://git.kernel.org/stable/c/5e13d0a37666955b6cfddc0f73cb40ed645b8a05
https://git.kernel.org/stable/c/f6c412dcfd76b0516d51aa847d8f4c7b70381b09
https://git.kernel.org/stable/c/735ee8582da3d239eb0c7a53adca61b79fb228b3
For details about the fixed versions of Linux vendors, see the security notices of Amazon Linux, Oracle Linux, Red Hat, SUSE and Ubuntu.
Note: Before fixing vulnerabilities, back up your files and conduct a thorough test.
Get more professional support at any time
Contact Us