CVE-2026-43037Disclosure(linux / linux_kernel)

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Prioritize remediation for linux linux_kernel systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

In the Linux kernel, the following vulnerability has been resolved: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() Oskar Kjos reported the following problem. ip4ip6_err() calls icmp_send() on a cloned skb whose cb[] was written by the IPv6 receive path as struct inet6_skb_parm. icmp_send() passes IPCB(skb2) to __ip_options_echo(), which interprets that cb[] region as struct inet_skb_parm (IPv4). The layouts differ: inet6_skb_parm.nhoff at offset 14 overlaps inet_skb_parm.opt.rr, producing a non-zero rr value. __ip_options_echo() then reads optlen from attacker-controlled packet data at sptr[rr+1] and copies that many bytes into dopt->__data, a fixed 40-byte stack buffer (IP_OPTIONS_DATA_FIXED_SIZE). To fix this we clear skb2->cb[], as suggested by Oskar Kjos. Also add minimal IPv4 header validation (version == 4, ihl >= 5).

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-787CWE-843

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • linux_kernel

Threat summary

  • Public PoC and exploit tooling are both present
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 4 mentions (2026-05-13); latest day: 1
  • 5 total mentions across 2 days

Affected systems

Vendors
Products
linux_kernel

1 version affected across 1 product

Deep dive

Activity timeline5 mentions / 2d
01234Mentions · 2026-05-13: 4Mentions · 2026-07-22: 1PoC Mentioned / Linked · 2026-05-13: 1Exploit Tool / Code · 2026-05-13: 1Technical Details · 2026-05-13: 4Technical Details · 2026-07-22: 105-1307-22
Signal classification3 categories
Disclosure
360.0%
PoC
120.0%
General
120.0%
Referenced assets18 URLs
Classification over time
DateTotalLabels
2026-05-134
Disclosure3PoC1
2026-07-221
General1
Full discourse5 posts
  • Lyrie.ai@lyrie_ai
    Disclosure

    --- Validated by the Lyrie Threat Intelligence Pipeline — 3 independent sources confirmed before publication. No speculation. CVE: CVE-2026-43037 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The text announces CVE‑2026‑43037 as a critical vulnerability, providing CVSS details but no PoC, exploit, or patch information.

    1000041
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE: CVE-2026-43037 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory In the Linux kernel, the following vulnerability has been resolved: ip6tunnel: clear skb2->cb[] in ip4ip6err() Oskar Kjos reported the…

    Post summary

    The text announces a critical vulnerability in the Linux kernel, providing technical details and CVSS scoring, indicating that it has been resolved but lacking explicit patch information or exploitation evidence.

    1000031
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CRITICAL: CVE-2026-43037 (CVSS 9.8) — multiple products. CVE: CVE-2026-43037 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The post announces a critical advisory for CVE‑2026‑43037 with a CVSS score of 9.8, affecting multiple products. No PoC, exploit, or patch details are provided.

    1000036
    210 followersView on X
  • Jan Guldentops@JanGuldentops
    General

    Alle individuele kwetsbaarheden uit de post met hun rechtstreekse link naar de European Vulnerability Database (EUVD) van ENISA: Active Directory Federation Services privilege escalation (CVE-2026-56155): https://euvd.enisa.europa.eu/vulnerability/CVE-2026-56155 BitLocker encryptieomzeiling (CVE-2026-50661): https://euvd.enisa.europa.eu/vulnerability/CVE-2026-50661 Remote Desktop kwetsbaarheid (CVE-2026-56190): https://euvd.enisa.europa.eu/vulnerability/CVE-2026-56190 Hyper-V virtual machine escape (CVE-2026-57092): https://euvd.enisa.europa.eu/vulnerability/CVE-2026-57092 Cisco VoIP kwetsbaarheid (CVE-2026-20150): https://euvd.enisa.europa.eu/vulnerability/CVE-2026-20150 Cisco SD-WAN kwetsbaarheid (CVE-2026-20182): https://euvd.enisa.europa.eu/vulnerability/CVE-2026-20182 Google Chrome bug 1 (CVE-2026-6811): https://euvd.enisa.europa.eu/vulnerability/CVE-2026-6811 Google Chrome bug 2 (CVE-2026-6812): https://euvd.enisa.europa.eu/vulnerability/CVE-2026-6812 Google Chrome bug 3 (CVE-2026-6813): https://euvd.enisa.europa.eu/vulnerability/CVE-2026-6813 Curl kwetsbaarheden range (CVE-2026-22834 t/m CVE-2026-22851): https://euvd.enisa.europa.eu/vulnerability/CVE-2026-22834 Fortinet FortiSandbox securitylek 1 (CVE-2026-25089): https://euvd.enisa.europa.eu/vulnerability/CVE-2026-25089 Fortinet FortiSandbox securitylek 2 (CVE-2026-39808): https://euvd.enisa.europa.eu/vulnerability/CVE-2026-39808 SonicWall SMA1000 server-side request forgery (CVE-2026-15409): https://euvd.enisa.europa.eu/vulnerability/CVE-2026-15409 SonicWall SMA1000 code injection en privesc (CVE-2026-15410): https://euvd.enisa.europa.eu/vulnerability/CVE-2026-15410 WordPress zero day (CVE-2026-63030): https://euvd.enisa.europa.eu/vulnerability/CVE-2026-63030 Linux Kernel ip6_tunnel RCE ( CVE-2026-43037) https://euvd.enisa.europa.eu/vulnerability/CVE-2026-43037 • • Linux kernel XFRM IPSEc ESP bug ( CVE-2026-43284 ) https://euvd.enisa.europa.eu/vulnerability/CVE-2026-43285

    Post summary

    The post enumerates a series of CVE identifiers with direct links to the EUVD, providing minimal vulnerability type information but lacking exploitation details, patches, or PoC references.

    00000171
    1.9K followersView on X
  • Lyrie.ai@lyrie_ai
    PoC

    https://lyrie.ai/research/research/cve-2026-43037-advisory #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The advisory discloses CVE‑2026‑43037, a critical remote‑code execution flaw, shares technical details and a proof‑of‑concept exploit, but does not report active exploitation or a vendor patch.

    0000025
    210 followersView on X
CPE platform detail7 entries

7 of 7 entries

PartVendorProductVersionTarget SWTarget HW
OSlinuxlinux_kernel---
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--

Explore more