In the Linux kernel, the following vulnerability has been resolved:

tcp: fix potential race in tcp_v6_syn_recv_sock()

Code in tcp_v6_syn_recv_sock() after the call to tcp_v4_syn_recv_sock()
is done too late.

After tcp_v4_syn_recv_sock(), the child socket is already visible
from TCP ehash table and other cpus might use it.

Since newinet->pinet6 is still pointing to the listener ipv6_pinfo
bad things can happen as syzbot found.

Move the problematic code in tcp_v6_mapped_child_init()
and call this new helper from tcp_v4_syn_recv_sock() before
the ehash insertion.

This allows the removal of one tcp_sync_mss(), since
tcp_v4_syn_recv_sock() will call it with the correct
context.

Project Subscriptions

Vendors Products
Linux Kernel Subscribe
Advisories
Source ID Title
Ubuntu USN Ubuntu USN USN-8630-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8631-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8633-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8634-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8635-1 Linux kernel (Azure) vulnerabilities
Ubuntu USN Ubuntu USN USN-8636-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8630-2 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8631-2 Linux kernel (Oracle) vulnerabilities
Ubuntu USN Ubuntu USN USN-8631-3 Linux kernel (NVIDIA Tegra IGX) vulnerabilities
Ubuntu USN Ubuntu USN USN-8633-2 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8631-4 Linux kernel (Azure CVM) vulnerabilities
Ubuntu USN Ubuntu USN USN-8645-1 Linux kernel (Oracle) vulnerabilities
Ubuntu USN Ubuntu USN USN-8630-3 Linux kernel (Oracle) vulnerabilities
Ubuntu USN Ubuntu USN USN-8636-2 Linux kernel (Oracle) vulnerabilities
Ubuntu USN Ubuntu USN USN-8656-1 Linux kernel (HWE) vulnerabilities
Ubuntu USN Ubuntu USN USN-8661-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8630-4 Linux kernel (AWS) vulnerabilities
Ubuntu USN Ubuntu USN USN-8666-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8662-2 Linux kernel (FIPS) vulnerabilities
Ubuntu USN Ubuntu USN USN-8667-1 Linux kernel (KVM) vulnerabilities
Ubuntu USN Ubuntu USN USN-8669-1 Linux kernel (NVIDIA) vulnerabilities
Ubuntu USN Ubuntu USN USN-8661-2 Linux kernel (Low Latency) vulnerabilities
Ubuntu USN Ubuntu USN USN-8630-5 Linux kernel (Raspberry Pi) vulnerabilities
Ubuntu USN Ubuntu USN USN-8666-2 Linux kernel (Azure) vulnerabilities
Ubuntu USN Ubuntu USN USN-8661-3 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8666-3 Linux kernel (GCP FIPS) vulnerabilities
Ubuntu USN Ubuntu USN USN-8661-4 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8715-1 Linux kernel (Oracle) vulnerabilities
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

References
Link Providers
https://access.redhat.com/errata/RHSA-2026:30129 cve-icon
https://access.redhat.com/errata/RHSA-2026:33215 cve-icon
https://access.redhat.com/errata/RHSA-2026:33285 cve-icon
https://access.redhat.com/errata/RHSA-2026:34094 cve-icon
https://access.redhat.com/errata/RHSA-2026:34443 cve-icon
https://access.redhat.com/errata/RHSA-2026:35863 cve-icon
https://access.redhat.com/errata/RHSA-2026:35894 cve-icon
https://access.redhat.com/errata/RHSA-2026:35896 cve-icon
https://access.redhat.com/errata/RHSA-2026:35904 cve-icon
https://access.redhat.com/errata/RHSA-2026:36073 cve-icon
https://access.redhat.com/errata/RHSA-2026:36216 cve-icon
https://access.redhat.com/errata/RHSA-2026:36348 cve-icon
https://access.redhat.com/errata/RHSA-2026:36349 cve-icon
https://access.redhat.com/errata/RHSA-2026:41236 cve-icon
https://access.redhat.com/security/cve/CVE-2026-43198 cve-icon
https://bugzilla.redhat.com/show_bug.cgi?id=2467228 cve-icon
https://git.kernel.org/stable/c/7178e2a8027423b2af17ab95df73a749a5b72e5b cve-icon cve-icon
https://git.kernel.org/stable/c/858d2a4f67ff69e645a43487ef7ea7f28f06deae cve-icon cve-icon
https://git.kernel.org/stable/c/9ed654e340f4c73bc6f0af2fbc90ac293e645ce0 cve-icon cve-icon
https://git.kernel.org/stable/c/a7e761ba55efaa9c49e0afdd304bb78167af3429 cve-icon cve-icon
https://git.kernel.org/stable/c/aef4a9ae95d1bc4f7897065011e6261026719aeb cve-icon cve-icon
https://git.kernel.org/stable/c/cd644e6dc72eec8d9d988717ea1c54f8668ded69 cve-icon cve-icon
https://git.kernel.org/stable/c/dad1fe7db6c6519138430ac8f5e589c18f83bfc9 cve-icon cve-icon
https://git.kernel.org/stable/c/fe89b2f05b854847784f91127319172945c1fadd cve-icon cve-icon
https://lore.kernel.org/linux-cve-announce/2026050645-CVE-2026-43198-0870@gregkh/T cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2026-43198 cve-icon
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-43198.json cve-icon
https://www.cve.org/CVERecord?id=CVE-2026-43198 cve-icon
History

Mon, 14 Sep 2026 12:00:00 +0000


Mon, 11 May 2026 20:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362
CPEs cpe:2.3:o:linux:linux_kernel:2.6.12:-:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.12:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.12:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.12:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.12:rc5:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc1:*:*:*:*:*:*

Fri, 08 May 2026 13:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.0, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Thu, 07 May 2026 04:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362

Thu, 07 May 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-821
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.0, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}

threat_severity

Important


Wed, 06 May 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362

Wed, 06 May 2026 12:15:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: tcp: fix potential race in tcp_v6_syn_recv_sock() Code in tcp_v6_syn_recv_sock() after the call to tcp_v4_syn_recv_sock() is done too late. After tcp_v4_syn_recv_sock(), the child socket is already visible from TCP ehash table and other cpus might use it. Since newinet->pinet6 is still pointing to the listener ipv6_pinfo bad things can happen as syzbot found. Move the problematic code in tcp_v6_mapped_child_init() and call this new helper from tcp_v4_syn_recv_sock() before the ehash insertion. This allows the removal of one tcp_sync_mss(), since tcp_v4_syn_recv_sock() will call it with the correct context.
Title tcp: fix potential race in tcp_v6_syn_recv_sock()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-14T11:58:18.188Z

Reserved: 2026-05-01T14:12:55.992Z

Link: CVE-2026-43198

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2026-05-06T12:16:38.857

Modified: 2026-09-14T12:17:40.837

Link: CVE-2026-43198

cve-icon Redhat

Severity : Important

Publid Date: 2026-05-06T00:00:00Z

Links: CVE-2026-43198 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-05-11T23:00:19Z

Weaknesses