cbcvebase.
CVE-2026-43190
published 2026-05-06

CVE-2026-43190: In the Linux kernel, the following vulnerability has been resolved: netfilter: xt_tcpmss: check remaining length before reading optlen Quoting reporter: In…

PriorityP343high8.2CVSS 3.1
AVNACLPRNUINSUCLINAH
EPSS
0.46%
37.2th percentile
In the Linux kernel, the following vulnerability has been resolved: netfilter: xt_tcpmss: check remaining length before reading optlen Quoting reporter: In net/netfilter/xt_tcpmss.c (lines 53-68), the TCP option parser reads op[i+1] directly without validating the remaining option length. If the last byte of the option field is not EOL/NOP (0/1), the code attempts to index op[i+1]. In the case where i + 1 == optlen, this causes an out-of-bounds read, accessing memory past the optlen boundary (either reading beyond the stack buffer _opt or the following payload).

Affected

44 ranges· showing 25
VendorProductVersion rangeFixed in
linuxlinux
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < f895191dc32c53eaf443b6443fe40945b2f92287f895191dc32c53eaf443b6443fe40945b2f92287
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < cd5beda7e0e32865e214f28034bb92c1cecff885cd5beda7e0e32865e214f28034bb92c1cecff885
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < eaedc0bc18be46fe7f58170e967959a932c4f824eaedc0bc18be46fe7f58170e967959a932c4f824
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 07a9b32eaae792ff7d0fcac14d8920c937c0a9c307a9b32eaae792ff7d0fcac14d8920c937c0a9c3
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 8b300f726640c48c3edfe9c453334dd801f4b74e8b300f726640c48c3edfe9c453334dd801f4b74e
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 5e13d0a37666955b6cfddc0f73cb40ed645b8a055e13d0a37666955b6cfddc0f73cb40ed645b8a05
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < f6c412dcfd76b0516d51aa847d8f4c7b70381b09f6c412dcfd76b0516d51aa847d8f4c7b70381b09
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 735ee8582da3d239eb0c7a53adca61b79fb228b3735ee8582da3d239eb0c7a53adca61b79fb228b3
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 2.6.12.1 < 5.10.2525.10.252
linuxlinux_kernel>= 5.11 < 5.15.2025.15.202
linuxlinux_kernel>= 5.16 < 6.1.1656.1.165
linuxlinux_kernel>= 6.13 < 6.18.166.18.16
linuxlinux_kernel>= 6.19 < 6.19.66.19.6
linuxlinux_kernel>= 6.2 < 6.6.1286.6.128
linuxlinux_kernel>= 6.7 < 6.12.756.12.75
ubuntulinux
ubuntulinux-aws
ubuntulinux-aws-6.8
ubuntulinux-aws-fips
ubuntulinux-azure-fips
ubuntulinux-fips
ubuntulinux-gcp

CVSS provenance

nvdv3.18.2HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
vendor_ubuntu8.8HIGH
vendor_redhat7.0HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.