PT-2026-36459 · Linux · Linux Kernel
CVE-2026-43042
·
Published
2026-05-01
·
Updated
2026-09-12
CVSS v3.1
7.1
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to March 2026
Description
An out-of-bounds (OOB) access issue exists in the Linux kernel within the MPLS implementation. RCU-protected codepaths, specifically the
mpls forward() and mpls dump routes() functions, can maintain an inconsistent view of platform labels versus platform label during a concurrent resize operation performed by the resize platform label table() function under platform mutex. Additionally, the mpls label ok() function is susceptible to this inconsistency. This flaw was discovered and exploited by the NebuSec security pipeline.Recommendations
Update the Linux kernel to a version released in March 2026 or later.
Exploit
Fix
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linux Kernel