CVE-2026-43083General(linux / linux_kernel)

LOWCVSS 9.1 · CRITICAL

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Patch linux linux_kernel systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In the Linux kernel, the following vulnerability has been resolved: net: ioam6: fix OOB and missing lock When trace->type.bit6 is set: if (trace->type.bit6) { ... queue = skb_get_tx_queue(dev, skb); qdisc = rcu_dereference(queue->qdisc); This code can lead to an out-of-bounds access of the dev->_tx[] array when is_input is true. In such a case, the packet is on the RX path and skb->queue_mapping contains the RX queue index of the ingress device. If the ingress device has more RX queues than the egress device (dev) has TX queues, skb_get_queue_mapping(skb) will exceed dev->num_tx_queues. Add a check to avoid this situation since skb_get_tx_queue() does not clamp the index. This issue has also revealed that per queue visibility cannot be accurate and will be replaced later as a new feature. While at it, add missing lock around qdisc_qstats_qlen_backlog(). The function __ioam6_fill_trace_data() is called from both softirq and process contexts, hence the use of spin_lock_bh() here.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-125

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • linux_kernel

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • General: 3 classified signals
  • Disclosure: 1 classified signal
  • Peaked at 4 mentions on most recent observed day (2026-05-13)
  • 5 total mentions across 2 days

Affected systems

Vendors
Products
linux_kernel

1 version affected across 1 product

Deep dive

Activity timeline5 mentions / 2d
01234Mentions · 2026-05-07: 1Mentions · 2026-05-13: 4Patch / Workaround · 2026-05-13: 1Technical Details · 2026-05-07: 1Technical Details · 2026-05-13: 305-0705-13
Signal classification3 categories
General
360.0%
Disclosure
120.0%
Patch
120.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-05-071
General1
2026-05-134
Disclosure1General2Patch1
Full discourse5 posts
  • Lyrie.ai@lyrie_ai
    Patch

    CVE: CVE-2026-43083 CVSS: 9.1 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H Severity: CRITICAL Status: Critical advisory In the Linux kernel, the following vulnerability has been resolved: net: ioam6: fix OOB and missing lock When trace->type.bit6 is set: if…

    Post summary

    A critical CVE-2026-43083 affecting the Linux kernel’s ioam6 component was disclosed, and a kernel patch addressing the out‑of‑bounds and missing lock issue has been released.

    1000035
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    if (trace->type.bit6) {... queue = skbgettxqueue(dev, skb); qdisc = rcudereference(queue->qdisc); CVE: CVE-2026-43083 CVSS: 9.1 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The note announces CVE-2026-43083 with a high CVSS score and critical severity, but contains no PoC, exploit code, or mitigation information.

    1000027
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    CVSS 9.1 CRITICAL · CVE-2026-43083 · 9.1 → 3.1 CVE: CVE-2026-43083 CVSS: 9.1 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The statement supplies CVE-2026-43083’s CVSS score, severity rating, and advisory status but lacks any mention of PoC, exploitation, patching, or active use.

    1000031
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2026-43083-advisory #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The text contains a link to an advisory for CVE-2026-43083 but does not provide any specific technical or exploit information.

    0000030
    210 followersView on X
  • WindowsForum@windowsforum
    General

    🪟 CVE-2026-43083: an IPv6 IOAM kernel bug with out-of-bounds transmit-queue access + missing lock. Not “catastrophic”… just the kind that ruins weekends in production. #Windows #Security https://windowsforum.com/threads/cve-2026-43083-ipv6-ioam-kernel-bug-why-windows-teams-must-triage-linux-risk.416792/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #WindowsPatchManagement #LinuxKernelSecurity #CveTriage #Ipv6Ioam https://t.co/TRVBmw5zns

    Post summary

    The post identifies a Linux kernel IPv6 IOAM bug (CVE‑2026‑43083), noting its out‑of‑bounds and missing lock issues, but offers no evidence of exploitation, PoC, or patch details.

    0000055
    1.1K followersView on X
CPE platform detail8 entries

8 of 8 entries

PartVendorProductVersionTarget SWTarget HW
OSlinuxlinux_kernel---
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--

Explore more