Red Hat disclosed CVE-2026-43037, a critical Linux kernel flaw in the ip6_tunnel component that can be triggered by malicious ICMPv6 error messages against IPv4-over-IPv6 tunnel handling. The bug stems from reusing a cloned socket buffer control block with incompatible IPv6 and IPv4 metadata layouts, a form of type confusion tracked by MITRE as CWE-843. In the vulnerable path, __ip_options_echo() can interpret attacker-controlled packet data as IPv4 option data and copy an attacker-influenced length into a fixed 40-byte stack buffer, creating stack-based memory corruption that can cause denial of service and potentially arbitrary code execution with kernel privileges.
Red Hat rated the issue CVSS 8.8 and published fixes across multiple RHEL and related product streams, including RHSA-2026:27719 for RHEL 6 Extended Lifecycle Support Extension. The upstream fix clears skb2->cb[] before calling icmp_send() and adds minimal IPv4 header validation requiring version 4 and an IHL of at least 5. Red Hat said updated kernel packages are available, including kernel-2.6.32-754.61.1.el6 for affected RHEL 6 ELS architectures, advised customers to reboot after applying updates, and recommended preventing the ip6_tunnel module from loading as a temporary mitigation until patches are installed.

See real exploitation activity before you spend the cycle.
11 events from the most recent confirmed update back to the earliest known activity.
Red Hat published RHSA-2026:27719, a critical kernel security advisory for Red Hat Enterprise Linux 6 Extended Lifecycle Support Extension. The advisory made updated kernel packages available and included a fix for CVE-2026-43037.
The Linux kernel CVE team announced CVE-2026-43037 for a flaw in ip4ip6_err() in net/ipv6/ip6_tunnel.c caused by reused skb cb[] data being interpreted as the wrong structure type. The announcement said the issue was introduced in Linux 2.6.22, credited Oskar Kjos for reporting it, and documented fixes across multiple stable branches including 5.10.253, 5.15.203, 6.1.168, 6.6.134, 6.12.81, 6.18.22, 6.19.12, and 7.0.
Red Hat published its security entry for CVE-2026-43037, describing a critical Linux kernel flaw in IPv4-over-IPv6 tunnel error handling tied to CWE-843. The entry says malicious ICMPv6 error messages can trigger a stack-based buffer overflow that may cause denial of service, information disclosure, or possible kernel-level code execution.
Red Hat listed CVE-2026-43037 as fixed for Red Hat Enterprise Linux 7 Extended Lifecycle Support kernel-rt in advisory RHSA-2026:41236.
Red Hat listed an additional fix for CVE-2026-43037 for NVIDIA for RHEL 10 in advisory RHSA-2026:33486.
Red Hat listed CVE-2026-43037 as fixed for the Red Hat Enterprise Linux 10 kpatch stream in advisory RHSA-2026:28742.
Red Hat listed CVE-2026-43037 as fixed for Red Hat Enterprise Linux 7 Extended Lifecycle Support in advisory RHSA-2026:27729.
Red Hat listed CVE-2026-43037 as fixed for NVIDIA for RHEL 10 in advisory RHSA-2026:25534.
Red Hat listed CVE-2026-43037 as fixed for Red Hat Enterprise Linux 10 in advisory RHSA-2026:25191.
Red Hat listed fixes for CVE-2026-43037 in RHSA-2026:25120 for RHEL 8 kernel-rt and RHSA-2026:25121 for the RHEL 8 kernel.
Red Hat listed CVE-2026-43037 as fixed for Red Hat Enterprise Linux 10.0 Extended Update Support in advisory RHSA-2026:24343.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
7 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceredhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcelore.kernel.org
Open sourcecwe.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.