In the Linux kernel, the following vulnerability has been resolved:
net/ipv6: ioam6: prevent schema length wraparound in trace fill
ioam6_fill_trace_data() stores the schema contribution to the trace
length in a u8. With bit 22 enabled and the largest schema payload,
sclen becomes 1 + 1020 / 4, wraps from 256 to 0, and bypasses the
remaining-space check. __ioam6_fill_trace_data() then positions the
write cursor without reserving the schema area but still copies the
4-byte schema header and the full schema payload, overrunning the trace
buffer.
Keep sclen in an unsigned int so the remaining-space check and the write
cursor calculation both see the full schema length.
References
Configurations
Configuration 1 (hide)
|
History
15 May 2026, 19:45
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://git.kernel.org/stable/c/184d2e9db27c0f76226b5cad16fe29510a5d2280 - Patch | |
| References | () https://git.kernel.org/stable/c/5e67ba9bb531e1ec6599a82a065dea9040b9ce50 - Patch | |
| References | () https://git.kernel.org/stable/c/77695a69baca9b99d95fad09fc78c2318736604f - Patch | |
| References | () https://git.kernel.org/stable/c/d1b041080086e91d3733a5438a8c51ad5d3d8e09 - Patch | |
| References | () https://git.kernel.org/stable/c/d6e1c9b02d85a4f1f4ba6d68e916d9b610a3ed7d - Patch | |
| References | () https://git.kernel.org/stable/c/e96d48b37708d53cbdc47f6f60b0714fc4a5f596 - Patch | |
| CPE | cpe:2.3:o:linux:linux_kernel:7.0:rc4:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:7.0:rc3:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:7.0:rc6:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:7.0:rc5:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:7.0:rc2:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:7.0:rc1:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:7.0:rc7:*:*:*:*:*:* |
|
| CWE | NVD-CWE-noinfo | |
| First Time |
Linux linux Kernel
Linux |
11 May 2026, 08:16
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
08 May 2026, 14:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-08 14:16
Updated : 2026-05-15 19:45
NVD link : CVE-2026-43341
Mitre link : CVE-2026-43341
CVE.ORG link : CVE-2026-43341
JSON object : View
Products Affected
linux
- linux_kernel
CWE
