PT-2026-36474 · Linux+1 · Linux Kernel+1

CVE-2026-43057

·

Published

2026-03-20

·

Updated

2026-08-20

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the network subsystem regarding the handling of tunneled traffic during IPV6 CSUM GSO fallback. The NETIF F IPV6 CSUM flag only supports checksum offload for packets without IPv6 extension headers, requiring packets with such headers to use software checksumming. Because TSO (TCP Segmentation Offload) depends on checksum offload, these packets must revert to GSO (Generic Segmentation Offload). The current implementation incorrectly checks only the network header length; however, for tunneled packets, the inner header length must be verified. Additionally, tunneled packets lacking an inner IP protocol, such as RFC 6951 SCTP in UDP, do not follow the standard IPv6 transport header structure and must also revert to the software GSO path.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Improperly Implemented Security Check for Standard

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-08740
CVE-2026-43057
ECHO-38C1-0E09-2F89
OESA-2026-2493
OESA-2026-2494
OESA-2026-2495
OPENSUSE-SU-2026:21388-1
SUSE-SU-2026:22742-1
SUSE-SU-2026:22769-1
SUSE-SU-2026:22809-1
SUSE-SU-2026:22810-1
SUSE-SU-2026:22812-1
SUSE-SU-2026:22835-1
SUSE-SU-2026:22903-1
SUSE-SU-2026:22904-1
SUSE-SU-2026:3130-1
SUSE-SU-2026:3166-1
USN-8567-1
USN-8574-1
USN-8574-2
USN-8574-3
USN-8595-1
USN-8595-2
USN-8595-3
USN-8596-1
USN-8606-1
USN-8607-1
USN-8608-1
USN-8609-1
USN-8619-1
USN-8665-1

Affected Products

Linux Kernel
Ubuntu