In the Linux kernel, the following vulnerability has been resolved: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() Oskar Kjos reported the following problem. ip4ip6_err() calls icmp_send() on a clon…
严重 CVSS 9.8
摘要
In the Linux kernel, the following vulnerability has been resolved: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() Oskar Kjos reported the following problem. ip4ip6_err() calls icmp_send() on a cloned skb whose cb[] was written by the IPv6 receive path as struct inet6_skb_parm. icmp_send() passes IPCB(skb2) to __ip_options_echo(), which interprets that cb[] region as struct inet_skb_parm (IPv4). The layouts differ: inet6_skb_parm.nhoff at offset 14 overlaps inet_skb_parm.opt.rr, producing a no…
中文摘要建设中,暂以英文摘要呈现(DR-003 v2)。
深度研判 · 自动通道
该漏洞尚未生成深度研判报告(DR-003 v2 AI pipeline 建设中)。
受影响产品
- :
数据来源
- NVD DATABASE
原始链接
- https://git.kernel.org/stable/c/1063515ce15ff31065c4e7f8265f4c2fd3c54876 Patch
- https://git.kernel.org/stable/c/2cc6e3b0fe0f0242d1f530a93a4924f48ab85ba5 Patch
- https://git.kernel.org/stable/c/2edfa31769a4add828a7e604b21cb82aaaa05925 Patch
- https://git.kernel.org/stable/c/4a622658f384b03560834cbe8ffcfe69a278f7c8 Patch
- https://git.kernel.org/stable/c/590f622669b97eaf7b57a1de7b0a6e68c5d8b2c3 Patch
- https://git.kernel.org/stable/c/a0c4ce9900a108eaf55d0f3b399cb55999647d39 Patch
- https://git.kernel.org/stable/c/d6621f60192fe10c047a4487be42a6f4c150707f Patch
- https://git.kernel.org/stable/c/ea9f65b27c8404e164848ebff1443310fd187629 Patch
- https://access.redhat.com/errata/RHSA-2026:22900
- https://access.redhat.com/errata/RHSA-2026:22940
- https://access.redhat.com/errata/RHSA-2026:22964
- https://access.redhat.com/errata/RHSA-2026:23224
- https://access.redhat.com/errata/RHSA-2026:23237
- https://access.redhat.com/errata/RHSA-2026:24343
- https://access.redhat.com/errata/RHSA-2026:25120
- https://access.redhat.com/errata/RHSA-2026:25121
- https://access.redhat.com/errata/RHSA-2026:25181
- https://access.redhat.com/errata/RHSA-2026:25186
- https://access.redhat.com/errata/RHSA-2026:25191
- https://access.redhat.com/errata/RHSA-2026:25193
- https://access.redhat.com/errata/RHSA-2026:25200
- https://access.redhat.com/errata/RHSA-2026:25217
- https://access.redhat.com/errata/RHSA-2026:25533
- https://access.redhat.com/errata/RHSA-2026:25534
- https://access.redhat.com/errata/RHSA-2026:26528
- https://access.redhat.com/errata/RHSA-2026:26535
- https://access.redhat.com/errata/RHSA-2026:26542
- https://access.redhat.com/errata/RHSA-2026:27719
- https://access.redhat.com/errata/RHSA-2026:27729
- https://access.redhat.com/errata/RHSA-2026:28738
- https://access.redhat.com/errata/RHSA-2026:28740
- https://access.redhat.com/errata/RHSA-2026:28741
- https://access.redhat.com/errata/RHSA-2026:28742
- https://access.redhat.com/errata/RHSA-2026:28748
- https://access.redhat.com/errata/RHSA-2026:28749
- https://access.redhat.com/errata/RHSA-2026:28750
- https://access.redhat.com/errata/RHSA-2026:28887
- https://access.redhat.com/errata/RHSA-2026:28962
- https://access.redhat.com/errata/RHSA-2026:33486
- https://access.redhat.com/errata/RHSA-2026:34098
- https://access.redhat.com/errata/RHSA-2026:41236
- https://access.redhat.com/security/cve/CVE-2026-43037
- https://bugzilla.redhat.com/show_bug.cgi?id=2464351
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-43037.json
时间线
- nvd_ingest NVD