A flaw in the Linux kernel's netfilter xt_tcpmss module, tracked as CVE-2026-43190, allows a remote attacker to trigger a one-byte out-of-bounds read with a specially crafted TCP packet. The bug is caused by improper validation of the remaining TCP option length before reading the option-length byte, and it can lead primarily to information disclosure with possible limited availability impact. The issue is not broadly reachable across all Linux systems; it affects hosts whose firewall rulesets use the tcpmss match.
The Linux kernel CVE team published fixes across multiple stable branches, including 5.10.252, 5.15.202, 6.1.165, 6.6.128, 6.12.75, 6.18.16, 6.19.6, and 7.0, and advised users to move to the latest stable kernel releases. Red Hat later shipped the fix in RHSA-2026:44694 for Red Hat Enterprise Linux 10.0 Extended Update Support kernel packages, alongside fixes for CVE-2026-31684 and CVE-2026-46152; updated packages include kernel version 6.12.0-55.92.1.el10_0 for x86_64, s390x, ppc64le, and aarch64, and Red Hat said affected systems should be rebooted after installation.

See real exploitation activity before you spend the cycle.
10 events from the most recent confirmed update back to the earliest known activity.
On 2026-07-23, Red Hat published RHSA-2026:44694 for Red Hat Enterprise Linux 10.0 Extended Update Support kernel packages, including a fix for CVE-2026-43190 alongside CVE-2026-31684 and CVE-2026-46152. The advisory rated the update Important, assessed the security impact as Moderate, and required a reboot after installation.
On 2026-05-28, Red Hat released fixes for CVE-2026-43190 in Red Hat Enterprise Linux 8 kernel, RHEL 8 kernel-rt, and RHEL 10 kernel through security errata including RHSA-2026:21706, RHSA-2026:21745, and RHSA-2026:21557. These were the first Red Hat product fixes listed for the vulnerability.
Red Hat published its CVE entry for CVE-2026-43190 on 2026-05-06, describing a remotely triggerable one-byte out-of-bounds read in the Linux kernel's netfilter xt_tcpmss module. Red Hat rated the issue Moderate, assigned a CVSS v3 score of 7.5, and said no mitigation meeting its Product Security criteria was available.
The Linux kernel CVE announcement stated the flaw had been fixed in stable releases 5.10.252, 5.15.202, 6.1.165, 6.6.128, 6.12.75, 6.18.16, 6.19.6, and 7.0. The advisory tied each fixed version to a corresponding upstream commit.
On 2026-05-06, the Linux kernel CVE team announced CVE-2026-43190 for an out-of-bounds read in netfilter's xt_tcpmss code caused by reading the TCP option length without validating remaining data. The notice identified affected code in net/netfilter/xt_tcpmss.c and advised users to update to stable kernels rather than cherry-pick commits.
On 2026-07-17, Red Hat issued RHSA-2026:41236 to fix CVE-2026-43190 in Red Hat Enterprise Linux 7 Extended Lifecycle Support kernel-rt packages.
Red Hat last modified its CVE-2026-43190 entry on 2026-07-01. The update reflected the vendor's ongoing tracking of affected products and fixes.
On 2026-06-22, Red Hat fixed CVE-2026-43190 in Red Hat Enterprise Linux 7 Extended Lifecycle Support kernel packages via RHSA-2026:27729.
On 2026-06-17, Red Hat issued RHSA-2026:26535 to fix CVE-2026-43190 in Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support and 8.4 Extended Update Support Long-Life Add-On kernel packages.
On 2026-06-12, Red Hat fixed CVE-2026-43190 for Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support and 8.6 Extended Update Support Long-Life Add-On kernel packages via RHSA-2026:25533.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 22 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
3 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceredhat.com
Open sourcelore.kernel.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.