CVE-2026-43198Disclosure(linux / linux_kernel)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch linux linux_kernel systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In the Linux kernel, the following vulnerability has been resolved: tcp: fix potential race in tcp_v6_syn_recv_sock() Code in tcp_v6_syn_recv_sock() after the call to tcp_v4_syn_recv_sock() is done too late. After tcp_v4_syn_recv_sock(), the child socket is already visible from TCP ehash table and other cpus might use it. Since newinet->pinet6 is still pointing to the listener ipv6_pinfo bad things can happen as syzbot found. Move the problematic code in tcp_v6_mapped_child_init() and call this new helper from tcp_v4_syn_recv_sock() before the ehash insertion. This allows the removal of one tcp_sync_mss(), since tcp_v4_syn_recv_sock() will call it with the correct context.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-362CWE-821

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • linux_kernel

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • General: 2 classified signals
  • Peaked 2d ago at 4 mentions (2026-05-14); latest day: 1
  • 7 total mentions across 4 days

Affected systems

Vendors
Products
linux_kernel

2 versions affected across 1 product

Deep dive

Activity timeline7 mentions / 4d
01234Mentions · 2026-05-07: 1Mentions · 2026-05-14: 4Mentions · 2026-09-27: 1Mentions · 2026-10-02: 1Patch / Workaround · 2026-05-07: 1Technical Details · 2026-05-07: 1Technical Details · 2026-05-14: 3Technical Details · 2026-09-27: 105-0705-1409-2710-02
Signal classification2 categories
Disclosure
466.7%
General
233.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-05-071
Disclosure1
2026-05-144
Disclosure2General2
2026-09-271
Disclosure1
Full discourse7 posts
  • Looptech Co.@l8ptech
    Disclosure

    🚨 أصدرت الهيئة الوطنية للأمن السيبراني تحذيرًا بشأن ثغرة أمنية عالية الخطورة في نواة Linux Kernel، والمصنّفة بالمعرّف CVE-2026-43198، والتي تؤثر على بعض إصدارات F5OS وقد تؤدي إلى تعطيل الخدمات (DoS). #الأمن_السيبراني #CyberSecurity #Linux #F5 #CVE202643198 https://t.co/zyOcVwGbYY

    Post summary

    NCSC issued a disclosure warning about CVE‑2026‑43198, a high‑severity Linux kernel vulnerability that could cause DoS on affected F5OS versions.

    00010113
    2.1K followersView on X
  • Lyrie.ai@lyrie_ai
    General

    CVE: CVE-2026-43198 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory In the Linux kernel, the following vulnerability has been resolved: tcp: fix potential race in tcpv6synrecvsock() Code in…

    Post summary

    The advisory notes a critical race condition in tcpv6synrecvsock() in the Linux kernel, but provides no exploit code, active exploitation evidence, or patch information.

    1000037
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    Code in tcpv6synrecvsock() after the call to tcpv4synrecvsock() is done too late. CVE: CVE-2026-43198 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The text announces a critical Linux kernel vulnerability (CVE-2026-43198) with detailed CVSS metrics, but provides no PoC, exploit code, active exploitation evidence, or patch information.

    1000024
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVSS 9.8 CRITICAL · CVE-2026-43198 · 9.8 → 3.1 CVE: CVE-2026-43198 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    Brief advisory for CVE-2026-43198 lists a critical CVSS 9.8 rating and severity, but lacks PoC, exploit, patch, or active exploitation information.

    1000035
    210 followersView on X
  • Hero.S@aka_ssy

    Debian’s Giant Kernel CVE List Has No Risk Map If you maintain a Debian stable machine, the actionable part is refreshingly short: upgrade the Linux package to 6.12.111-1. Debian says that release fixes a large batch of kernel vulnerabilities capable of causing privilege escalation, denial of service, or information disclosure. Everything after that gets murkier. The advisory dated September 29, 2026 includes identifiers from 2024, 2025, and 2026, among them CVE-2024-52560, CVE-2025-21817, CVE-2026-23137, and CVE-2026-43198. It also contains a long run of CVE-2026-8xxxx and 9xxxx entries. But the supplied list is cut off, and the notice does not explain each bug’s mechanics, severity, prerequisites, or exact affected configurations. That makes the sheer CVE count a pretty lousy risk meter. Kernel vulnerabilities are not one interchangeable blob: a privilege-escalation bug may require an attacker to already have local access, while a denial-of-service flaw may depend on a particular subsystem being enabled or reachable. An information leak can likewise range from narrowly constrained to genuinely ugly. The advisory’s three broad impact categories tell administrators what could go wrong, but not which machines face which path. The mixed CVE years are easy to overread too. An identifier is not a severity score, nor does its year alone explain when a bug reached Debian, when a fix became available, or how long a specific stable installation was exposed. The announcement does not provide enough chronology to make those judgments. Even the attached PGP signature, which uses SHA-512, solves a different problem. Given a trusted signing key, it helps establish that the message is authentic and unmodified. It does not turn the CVE list into a prioritization guide. So this is a patch-first, investigate-in-parallel advisory. Most trixie users have a clear destination version and little reason to wait for every CVE to receive a readable postmortem. Operators who cannot update immediately have the harder job: checking Debian’s Security Tracker for the affected subsystems and conditions relevant to their systems. The bulletin supplies the fix; the tracker still has to supply the risk map.

    00000105
    3.8K followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2026-43198-advisory #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The post references an advisory for CVE-2026-43198 but provides no additional information or technical details.

    0000020
    210 followersView on X
  • WindowsForum@windowsforum
    Disclosure

    🪟 CVE-2026-43198 is the “oops, your packet raced your initialization” kind of bug—because in kernels, visibility/order across CPUs is security. For fleets: patch rollout timing matters. #Linux #Security #WindowsForum https://windowsforum.com/threads/cve-2026-43198-linux-tcp-ipv6-race-fix-why-ordering-matters-for-fleets.416741/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #RaceCondition #LinuxKernelSecurity https://t.co/JfESPzzlbP

    Post summary

    The post announces a newly disclosed race condition bug in the Linux kernel (CVE‑2026‑43198) and stresses the importance of timely patch deployment for affected fleets.

    0000044
    1.1K followersView on X
CPE platform detail7 entries

7 of 7 entries

PartVendorProductVersionTarget SWTarget HW
OSlinuxlinux_kernel---
OSlinuxlinux_kernel2.6.12--
OSlinuxlinux_kernel2.6.12--
OSlinuxlinux_kernel2.6.12--
OSlinuxlinux_kernel2.6.12--
OSlinuxlinux_kernel2.6.12--
OSlinuxlinux_kernel7.0--

Explore more