Description
In the Linux kernel, the following vulnerability has been resolved:

tcp: fix potential race in tcp_v6_syn_recv_sock()

Code in tcp_v6_syn_recv_sock() after the call to tcp_v4_syn_recv_sock()
is done too late.

After tcp_v4_syn_recv_sock(), the child socket is already visible
from TCP ehash table and other cpus might use it.

Since newinet->pinet6 is still pointing to the listener ipv6_pinfo
bad things can happen as syzbot found.

Move the problematic code in tcp_v6_mapped_child_init()
and call this new helper from tcp_v4_syn_recv_sock() before
the ehash insertion.

This allows the removal of one tcp_sync_mss(), since
tcp_v4_syn_recv_sock() will call it with the correct
context.
Published: 2026-05-06
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Ubuntu USN Ubuntu USN USN-8630-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8631-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8633-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8634-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8635-1 Linux kernel (Azure) vulnerabilities
Ubuntu USN Ubuntu USN USN-8636-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8630-2 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8631-2 Linux kernel (Oracle) vulnerabilities
Ubuntu USN Ubuntu USN USN-8631-3 Linux kernel (NVIDIA Tegra IGX) vulnerabilities
Ubuntu USN Ubuntu USN USN-8633-2 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8631-4 Linux kernel (Azure CVM) vulnerabilities
Ubuntu USN Ubuntu USN USN-8645-1 Linux kernel (Oracle) vulnerabilities
Ubuntu USN Ubuntu USN USN-8630-3 Linux kernel (Oracle) vulnerabilities
Ubuntu USN Ubuntu USN USN-8636-2 Linux kernel (Oracle) vulnerabilities
Ubuntu USN Ubuntu USN USN-8656-1 Linux kernel (HWE) vulnerabilities
Ubuntu USN Ubuntu USN USN-8661-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8630-4 Linux kernel (AWS) vulnerabilities
Ubuntu USN Ubuntu USN USN-8666-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8662-2 Linux kernel (FIPS) vulnerabilities
Ubuntu USN Ubuntu USN USN-8667-1 Linux kernel (KVM) vulnerabilities
Ubuntu USN Ubuntu USN USN-8669-1 Linux kernel (NVIDIA) vulnerabilities
Ubuntu USN Ubuntu USN USN-8661-2 Linux kernel (Low Latency) vulnerabilities
Ubuntu USN Ubuntu USN USN-8630-5 Linux kernel (Raspberry Pi) vulnerabilities
Ubuntu USN Ubuntu USN USN-8666-2 Linux kernel (Azure) vulnerabilities
Ubuntu USN Ubuntu USN USN-8661-3 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8666-3 Linux kernel (GCP FIPS) vulnerabilities
Ubuntu USN Ubuntu USN USN-8661-4 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8715-1 Linux kernel (Oracle) vulnerabilities
References
Link Providers
https://access.redhat.com/errata/RHSA-2026:30129 cve-icon
https://access.redhat.com/errata/RHSA-2026:33215 cve-icon
https://access.redhat.com/errata/RHSA-2026:33285 cve-icon
https://access.redhat.com/errata/RHSA-2026:34094 cve-icon
https://access.redhat.com/errata/RHSA-2026:34443 cve-icon
https://access.redhat.com/errata/RHSA-2026:35863 cve-icon
https://access.redhat.com/errata/RHSA-2026:35894 cve-icon
https://access.redhat.com/errata/RHSA-2026:35896 cve-icon
https://access.redhat.com/errata/RHSA-2026:35904 cve-icon
https://access.redhat.com/errata/RHSA-2026:36073 cve-icon
https://access.redhat.com/errata/RHSA-2026:36216 cve-icon
https://access.redhat.com/errata/RHSA-2026:36348 cve-icon
https://access.redhat.com/errata/RHSA-2026:36349 cve-icon
https://access.redhat.com/errata/RHSA-2026:41236 cve-icon
https://access.redhat.com/security/cve/CVE-2026-43198 cve-icon
https://bugzilla.redhat.com/show_bug.cgi?id=2467228 cve-icon
https://git.kernel.org/stable/c/7178e2a8027423b2af17ab95df73a749a5b72e5b cve-icon cve-icon
https://git.kernel.org/stable/c/858d2a4f67ff69e645a43487ef7ea7f28f06deae cve-icon cve-icon
https://git.kernel.org/stable/c/9ed654e340f4c73bc6f0af2fbc90ac293e645ce0 cve-icon cve-icon
https://git.kernel.org/stable/c/a7e761ba55efaa9c49e0afdd304bb78167af3429 cve-icon cve-icon
https://git.kernel.org/stable/c/aef4a9ae95d1bc4f7897065011e6261026719aeb cve-icon cve-icon
https://git.kernel.org/stable/c/cd644e6dc72eec8d9d988717ea1c54f8668ded69 cve-icon cve-icon
https://git.kernel.org/stable/c/dad1fe7db6c6519138430ac8f5e589c18f83bfc9 cve-icon cve-icon
https://git.kernel.org/stable/c/fe89b2f05b854847784f91127319172945c1fadd cve-icon cve-icon
https://lore.kernel.org/linux-cve-announce/2026050645-CVE-2026-43198-0870@gregkh/T cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2026-43198 cve-icon
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-43198.json cve-icon
https://www.cve.org/CVERecord?id=CVE-2026-43198 cve-icon
History

Mon, 14 Sep 2026 12:00:00 +0000


Mon, 11 May 2026 20:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362
CPEs cpe:2.3:o:linux:linux_kernel:2.6.12:-:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.12:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.12:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.12:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.12:rc5:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc1:*:*:*:*:*:*

Fri, 08 May 2026 13:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.0, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Thu, 07 May 2026 04:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362

Thu, 07 May 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-821
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.0, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}

threat_severity

Important


Wed, 06 May 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362

Wed, 06 May 2026 12:15:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: tcp: fix potential race in tcp_v6_syn_recv_sock() Code in tcp_v6_syn_recv_sock() after the call to tcp_v4_syn_recv_sock() is done too late. After tcp_v4_syn_recv_sock(), the child socket is already visible from TCP ehash table and other cpus might use it. Since newinet->pinet6 is still pointing to the listener ipv6_pinfo bad things can happen as syzbot found. Move the problematic code in tcp_v6_mapped_child_init() and call this new helper from tcp_v4_syn_recv_sock() before the ehash insertion. This allows the removal of one tcp_sync_mss(), since tcp_v4_syn_recv_sock() will call it with the correct context.
Title tcp: fix potential race in tcp_v6_syn_recv_sock()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-14T11:58:18.188Z

Reserved: 2026-05-01T14:12:55.992Z

Link: CVE-2026-43198

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2026-05-06T12:16:38.857

Modified: 2026-09-14T12:17:40.837

Link: CVE-2026-43198

cve-icon Redhat

Severity : Important

Publid Date: 2026-05-06T00:00:00Z

Links: CVE-2026-43198 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-05-11T23:00:19Z

Weaknesses