CVE 9.8 CRITICAL

net/ipv6: ioam6: prevent schema length wraparound in trace fill_CVE-2026-43341

9.8 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

In the Linux kernel, the following vulnerability has been resolved:

net/ipv6: ioam6: prevent schema length wraparound in trace fill

ioam6_fill_trace_data() stores the schema contribution to the trace
length in a u8. With bit 22 enabled and the largest schema payload,
sclen becomes 1 + 1020 / 4, wraps from 256 to 0, and bypasses the
remaining-space check. __ioam6_fill_trace_data() then positions the
write cursor without reserving the schema area but still copies the
4-byte schema header and the full schema payload, overrunning the trace
buffer.

Keep sclen in an unsigned int so the remaining-space check and the write
cursor calculation both see the full schema length.

Basic Information

ID CVE-2026-43341
Source Linux
Published May 8, 2026 at 13:37
Modified May 11, 2026 at 06:33

Affected Product

Vendor Linux
Product Linux
Version 8c6f6fa6772696be0c047a711858084b38763728
Affected Versions Linux Linux 8c6f6fa6772696be0c047a711858084b38763728
Linux Linux 8c6f6fa6772696be0c047a711858084b38763728
Linux Linux 8c6f6fa6772696be0c047a711858084b38763728
Linux Linux 8c6f6fa6772696be0c047a711858084b38763728
Linux Linux 8c6f6fa6772696be0c047a711858084b38763728
Linux Linux 8c6f6fa6772696be0c047a711858084b38763728
Linux Linux 5.15

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.