CVE-2026-43037 is a stack-based buffer overflow in the Linux kernel IPv6 tunnel error handler, ip4ip6_err(). A cloned socket buffer retains control-buffer metadata written by the IPv6 receive path as inet6_skb_parm, but ICMP error processing subsequently interprets the same region as IPv4 inet_skb_parm data. A layout overlap can make the IPv4 source-route option field appear nonzero. IPv4 option echo handling then obtains an option length from attacker-controlled packet data and copies that quantity into a fixed 40-byte stack buffer. The upstream correction clears the cloned buffer control area before use and adds minimal validation that the encapsulated IPv4 header has version 4 and an Internet Header Length of at least 5.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
54 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A vulnerability addressed by the Ubuntu USN-8667-1 kernel security update.
A Linux kernel ip6_tunnel vulnerability involving improper handling of skb control buffer state in ip4ip6_err().
A Linux kernel vulnerability in ip6_tunnel/ip4ip6_err() addressed in this OpenShift security update.
A Linux kernel vulnerability in ip6_tunnel related to clearing skb2->cb[] in ip4ip6_err(). It is included as one of the critical security fixes in this OpenShift Container Platform 4.15.66 update.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.