CVE-2026-43501

In the Linux kernel, the following vulnerability has been resolved: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows ipv6_rpl_srh_rcv() decompresses an RFC 6554 Source Routing Header, swaps the next segment into ipv6_hdr->daddr, recompresses, then pulls the old header and pushes the new one plus the IPv6 header back. The recompressed header can be larger than the received one when the swap reduces the common-prefix length the segments share with daddr (CmprI=0, CmprE>0, seg[0][0] != daddr[0] gives the maximum +8 bytes). pskb_expand_head() was gated on segments_left == 0, so on earlier segments the push consumed unchecked headroom. Once skb_push() leaves fewer than skb->mac_len bytes in front of data, skb_mac_header_rebuild()'s call to: skb_set_mac_header(skb, -skb->mac_len); will store (data - head) - mac_len into the u16 mac_header field, which wraps to ~65530, and the following memmove() writes mac_len bytes ~64KiB past skb->head. A single AF_INET6/SOCK_RAW/IPV6_HDRINCL packet over lo with a two segment type-3 SRH (CmprI=0, CmprE=15) reaches headroom 8 after one pass; KASAN reports a 14-byte OOB write in ipv6_rthdr_rcv. Fix this by expanding the head whenever the remaining room is less than the push size plus mac_len, and request that much extra so the rebuilt MAC header fits afterwards.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:*

History

23 Jul 2026, 16:10

Type Values Removed Values Added
Summary
  • (es) En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta: ipv6: rpl: reservar espacio libre (headroom) para mac_len cuando el SRH recomprimido crece ipv6_rpl_srh_rcv() descomprime un encabezado de enrutamiento de origen (Source Routing Header) RFC 6554, intercambia el siguiente segmento en ipv6_hdr->daddr, recomprime, luego extrae el encabezado antiguo y empuja el nuevo más el encabezado IPv6 de vuelta. El encabezado recomprimido puede ser más grande que el recibido cuando el intercambio reduce la longitud del prefijo común que los segmentos comparten con daddr (CmprI=0, CmprE>0, seg[0][0] != daddr[0] da un máximo de +8 bytes). pskb_expand_head() estaba condicionado a segments_left == 0, así que en segmentos anteriores el empuje consumió espacio libre (headroom) sin verificar. Una vez que skb_push() deja menos de skb->mac_len bytes delante de los datos, la llamada de skb_mac_header_rebuild() a: skb_set_mac_header(skb, -skb->mac_len); almacenará (data - head) - mac_len en el campo u16 mac_header, que se ajusta a ~65530, y el siguiente memmove() escribe mac_len bytes ~64KiB más allá de skb->head. Un único paquete AF_INET6/SOCK_RAW/IPV6_HDRINCL sobre lo con un SRH tipo 3 de dos segmentos (CmprI=0, CmprE=15) alcanza un espacio libre (headroom) de 8 después de una pasada; KASAN informa de una escritura OOB de 14 bytes en ipv6_rthdr_rcv. Solucione esto expandiendo el encabezado siempre que el espacio restante sea menor que el tamaño del empuje más mac_len, y solicite esa cantidad extra para que el encabezado MAC reconstruido quepa después.

02 Jul 2026, 12:17

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:34094 -
  • () https://access.redhat.com/errata/RHSA-2026:34095 -

01 Jul 2026, 13:17

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:33900 -

30 Jun 2026, 03:19

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:25191 -
  • () https://access.redhat.com/errata/RHSA-2026:25217 -
  • () https://access.redhat.com/errata/RHSA-2026:27713 -
  • () https://access.redhat.com/errata/RHSA-2026:27731 -
  • () https://access.redhat.com/security/cve/CVE-2026-43501 -
  • () https://bugzilla.redhat.com/show_bug.cgi?id=2480457 -
  • () https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-43501.json -
CWE CWE-131

26 Jun 2026, 17:28

Type Values Removed Values Added
References () https://git.kernel.org/stable/c/0a9e8053f1f8a8e1bfc1dd61ffe67be6c1180402 - () https://git.kernel.org/stable/c/0a9e8053f1f8a8e1bfc1dd61ffe67be6c1180402 - Patch
References () https://git.kernel.org/stable/c/4babc2d9fda2df43823b85d08a0180b68f1b0854 - () https://git.kernel.org/stable/c/4babc2d9fda2df43823b85d08a0180b68f1b0854 - Patch
References () https://git.kernel.org/stable/c/7398ebefbfd4f8a31d4f665a4213302fa995494b - () https://git.kernel.org/stable/c/7398ebefbfd4f8a31d4f665a4213302fa995494b - Patch
References () https://git.kernel.org/stable/c/8e8be63465a5e80394c70324603dfea1bfdad48f - () https://git.kernel.org/stable/c/8e8be63465a5e80394c70324603dfea1bfdad48f - Patch
References () https://git.kernel.org/stable/c/9e6bf146b55999a095bb14f73a843942456d1adc - () https://git.kernel.org/stable/c/9e6bf146b55999a095bb14f73a843942456d1adc - Patch
References () https://git.kernel.org/stable/c/bde199c72d319a4e207f88daabc888317504e2fb - () https://git.kernel.org/stable/c/bde199c72d319a4e207f88daabc888317504e2fb - Patch
References () https://git.kernel.org/stable/c/be1fa0aa9b4fdd5a8b7a61ba520a690a68391e6e - () https://git.kernel.org/stable/c/be1fa0aa9b4fdd5a8b7a61ba520a690a68391e6e - Patch
References () https://git.kernel.org/stable/c/c261d07a80576dc8ccf394ef8f074f8c67a06b37 - () https://git.kernel.org/stable/c/c261d07a80576dc8ccf394ef8f074f8c67a06b37 - Patch
CPE cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:*
First Time Linux linux Kernel
Linux
CWE CWE-787

01 Jun 2026, 17:17

Type Values Removed Values Added
References
  • () https://git.kernel.org/stable/c/0a9e8053f1f8a8e1bfc1dd61ffe67be6c1180402 -
  • () https://git.kernel.org/stable/c/bde199c72d319a4e207f88daabc888317504e2fb -
  • () https://git.kernel.org/stable/c/be1fa0aa9b4fdd5a8b7a61ba520a690a68391e6e -

30 May 2026, 11:17

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8

21 May 2026, 13:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-21 13:16

Updated : 2026-07-23 16:10


NVD link : CVE-2026-43501

Mitre link : CVE-2026-43501

CVE.ORG link : CVE-2026-43501


JSON object : View

Products Affected

linux

  • linux_kernel
CWE
CWE-787

Out-of-bounds Write

CWE-131

Incorrect Calculation of Buffer Size