cbcvebase.
CVE-2026-43456
published 2026-05-08

CVE-2026-43456: In the Linux kernel, the following vulnerability has been resolved: bonding: fix type confusion in bond_setup_by_slave() kernel BUG at net/core/skbuff.c:2306!…

PriorityP340high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.16%
5.6th percentile
In the Linux kernel, the following vulnerability has been resolved: bonding: fix type confusion in bond_setup_by_slave() kernel BUG at net/core/skbuff.c:2306! Oops: invalid opcode: 0000 [#1] SMP KASAN NOPTI RIP: 0010:pskb_expand_head+0xa08/0xfe0 net/core/skbuff.c:2306 RSP: 0018:ffffc90004aff760 EFLAGS: 00010293 RAX: 0000000000000000 RBX: ffff88807e3c8780 RCX: ffffffff89593e0e RDX: ffff88807b7c4900 RSI: ffffffff89594747 RDI: ffff88807b7c4900 RBP: 0000000000000820 R08: 0000000000000005 R09: 0000000000000000 R10: 00000000961a63e0 R11: 0000000000000000 R12: ffff88807e3c8780 R13: 00000000961a6560 R14: dffffc0000000000 R15: 00000000961a63e0 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00007fe1a0ed8df0 CR3: 000000002d816000 CR4: 00000000003526f0 Call Trace: ipgre_header+0xdd/0x540 net/ipv4/ip_gre.c:900 dev_hard_header include/linux/netdevice.h:3439 [inline] packet_snd net/packet/af_packet.c:3028 [inline] packet_sendmsg+0x3ae5/0x53c0 net/packet/af_packet.c:3108 sock_sendmsg_nosec net/socket.c:727 [inline] __sock_sendmsg net/socket.c:742 [inline] ____sys_sendmsg+0xa54/0xc30 net/socket.c:2592 ___sys_sendmsg+0x190/0x1e0 net/socket.c:2646 __sys_sendmsg+0x170/0x220 net/socket.c:2678 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline] do_syscall_64+0x106/0xf80 arch/x86/entry/syscall_64.c:94 entry_SYSCALL_64_after_hwframe+0x77/0x7f RIP: 0033:0x7fe1a0e6c1a9 When a non-Ethernet device (e.g. GRE tunnel) is enslaved to a bond, bond_setup_by_slave() directly copies the slave's header_ops to the bond device: bond_dev->header_ops = slave_dev->header_ops; This causes a type confusion when dev_hard_header() is later called on the bond device. Functions like ipgre_header(), ip6gre_header(),all use netdev_priv(dev) to access their device-specific private data. When called with the bond device, netdev_priv() returns the bond's private data (struct bonding) instead of the expected type (e.g. struct ip_tunnel), leading to garbage values being read and kernel crashes. Fix this

Affected

29 ranges· showing 25
VendorProductVersion rangeFixed in
linuxlinux
linuxlinux>= 1284cd3a2b740d0118458d2ea470a1e5bc19b187 < 5d0fb9806ab6cf2c3cfba0e1b8c701da65e25af85d0fb9806ab6cf2c3cfba0e1b8c701da65e25af8
linuxlinux>= 1284cd3a2b740d0118458d2ea470a1e5bc19b187 < 9baf26a91565b7bb2b1d9f99aaf884a2b28c2f6d9baf26a91565b7bb2b1d9f99aaf884a2b28c2f6d
linuxlinux>= 1284cd3a2b740d0118458d2ea470a1e5bc19b187 < 6ac890f1d60ac3707ee8dae15a67d9a833e499566ac890f1d60ac3707ee8dae15a67d9a833e49956
linuxlinux>= 1284cd3a2b740d0118458d2ea470a1e5bc19b187 < 95597d11dc8bddb2b9a051c9232000bfbb5e43ba95597d11dc8bddb2b9a051c9232000bfbb5e43ba
linuxlinux>= 1284cd3a2b740d0118458d2ea470a1e5bc19b187 < 950803f7254721c1c15858fbbfae3deaaeeecb11950803f7254721c1c15858fbbfae3deaaeeecb11
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 2.6.24 < 6.12.786.12.78
linuxlinux_kernel>= 6.13 < 6.18.196.18.19
linuxlinux_kernel>= 6.19 < 6.19.96.19.9
ubuntulinux
ubuntulinux-fips
ubuntulinux-gcp
ubuntulinux-gcp-6.8
ubuntulinux-gcp-fips
ubuntulinux-gke
ubuntulinux-gkeop
ubuntulinux-lowlatency
ubuntulinux-lowlatency-hwe-6.8
ubuntulinux-nvidia
ubuntulinux-nvidia-6.8
ubuntulinux-nvidia-lowlatency

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_redhat7.0MEDIUM
vendor_ubuntu2.0LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.