Software
Service
Insights
Case & Story
Dev Platform
Sign In
Public Notices
Linux Kernel Out-of-Bounds Read Vulnerability (CVE-2026-43190)
Jul. 9, 2026 GMT+08:00
1.Overview

Recently, an out-of-bounds read vulnerability (CVE-2026-43190) has been disclosed in the Linux kernel netfilter xt_tcpmss module. The TCP option parser reads op[i+1] without validating the remaining length. When the last option byte is not EOL(0) or NOP(1) and i + 1 == optlen, the code reads past the optlen boundary, causing an out-of-bounds read. A remote attacker can trigger this by sending crafted TCP packets, leading to information disclosure or denial of service.

Linux kernel is the core component of Linux operating systems. Check your system and implement timely security hardening.

Reference:

https://nvd.nist.gov/vuln/detail/CVE-2026-43190

https://lore.kernel.org/linux-cve-announce/2026050642-CVE-2026-43190-f1c9@gregkh/

2.Severity

important

(Severity: low, medium, important, and critical)

3.Affected Products

Affected versions:

2.6.12 <= Linux kernel < 5.10.252

5.11 <= Linux kernel < 5.15.202

5.16 <= Linux kernel < 6.1.165

6.2 <= Linux kernel < 6.6.128

6.7 <= Linux kernel < 6.12.75

6.13 <= Linux kernel < 6.18.16

6.19 <= Linux kernel < 6.19.6

Affected OSs:

All Linux-based system distributions running an affected kernel version are impacted, including but not limited to Ubuntu, Red Hat Enterprise Linux, Oracle Linux, SUSE, Amazon Linux, and other embedded/custom systems.

Security versions:

Linux Kernel 5.10 >= 5.10.252 (commit f895191dc32c)

Linux Kernel 5.15 >= 5.15.202 (commit cd5beda7e0e3)

Linux Kernel 6.1 >= 6.1.165 (commit eaedc0bc18be)

Linux Kernel 6.6 >= 6.6.128 (commit 07a9b32eaae7)

Linux Kernel 6.12 >= 6.12.75 (commit 8b300f726640)

Linux Kernel 6.18 >= 6.18.16 (commit 5e13d0a37666)

Linux Kernel 6.19 >= 6.19.6 (commit f6c412dcfd76)

Linux Kernel 7.0 (commit 735ee8582da3)

5.Technical Support

Get more professional support at any time

Contact Us

Email: GlobalTechnicalService@iwhalecloud.com
Contact Us