9.8
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Description
In the Linux kernel, the following vulnerability has been resolved:
net/ipv6: ioam6: prevent schema length wraparound in trace fill
ioam6_fill_trace_data() stores the schema contribution to the trace
length in a u8. With bit 22 enabled and the largest schema payload,
sclen becomes 1 + 1020 / 4, wraps from 256 to 0, and bypasses the
remaining-space check. __ioam6_fill_trace_data() then positions the
write cursor without reserving the schema area but still copies the
4-byte schema header and the full schema payload, overrunning the trace
buffer.
Keep sclen in an unsigned int so the remaining-space check and the write
cursor calculation both see the full schema length.
net/ipv6: ioam6: prevent schema length wraparound in trace fill
ioam6_fill_trace_data() stores the schema contribution to the trace
length in a u8. With bit 22 enabled and the largest schema payload,
sclen becomes 1 + 1020 / 4, wraps from 256 to 0, and bypasses the
remaining-space check. __ioam6_fill_trace_data() then positions the
write cursor without reserving the schema area but still copies the
4-byte schema header and the full schema payload, overrunning the trace
buffer.
Keep sclen in an unsigned int so the remaining-space check and the write
cursor calculation both see the full schema length.
Basic Information
ID
CVE-2026-43341
Source
Linux
Published
May 8, 2026 at 13:37
Modified
May 11, 2026 at 06:33
Affected Product
Vendor
Linux
Product
Linux
Version
8c6f6fa6772696be0c047a711858084b38763728
Affected Versions
Linux Linux 8c6f6fa6772696be0c047a711858084b38763728
Linux Linux 8c6f6fa6772696be0c047a711858084b38763728
Linux Linux 8c6f6fa6772696be0c047a711858084b38763728
Linux Linux 8c6f6fa6772696be0c047a711858084b38763728
Linux Linux 8c6f6fa6772696be0c047a711858084b38763728
Linux Linux 8c6f6fa6772696be0c047a711858084b38763728
Linux Linux 5.15
Linux Linux 8c6f6fa6772696be0c047a711858084b38763728
Linux Linux 8c6f6fa6772696be0c047a711858084b38763728
Linux Linux 8c6f6fa6772696be0c047a711858084b38763728
Linux Linux 8c6f6fa6772696be0c047a711858084b38763728
Linux Linux 8c6f6fa6772696be0c047a711858084b38763728
Linux Linux 5.15
References
- git.kernel.org /stable/c/e96d48b37708d53cbdc47f6f60b0714fc4a5f596
- git.kernel.org /stable/c/d1b041080086e91d3733a5438a8c51ad5d3d8e09
- git.kernel.org /stable/c/77695a69baca9b99d95fad09fc78c2318736604f
- git.kernel.org /stable/c/184d2e9db27c0f76226b5cad16fe29510a5d2280
- git.kernel.org /stable/c/d6e1c9b02d85a4f1f4ba6d68e916d9b610a3ed7d
- git.kernel.org /stable/c/5e67ba9bb531e1ec6599a82a065dea9040b9ce50