CVE-2026-43190
netfilter: xt_tcpmss: check remaining length before reading optlen
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
In the Linux kernel, the following vulnerability has been resolved: netfilter: xt_tcpmss: check remaining length before reading optlen Quoting reporter: In net/netfilter/xt_tcpmss.c (lines 53-68), the TCP option parser reads op[i+1] directly without validating the remaining option length. If the last byte of the option field is not EOL/NOP (0/1), the code attempts to index op[i+1]. In the case where i + 1 == optlen, this causes an out-of-bounds read, accessing memory past the optlen boundary (either reading beyond the stack buffer _opt or the following payload).
| Vendor | linux |
| Product | linux |
| Ecosystems | |
| Industries | Technology |
| Published | May 6, 2026 |
Stay Ahead of the Next One
Get instant alerts for linux linux
Be the first to know when new unknown vulnerabilities affecting linux linux are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Linux / Linux
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < f895191dc32c53eaf443b6443fe40945b2f92287 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < cd5beda7e0e32865e214f28034bb92c1cecff885 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < eaedc0bc18be46fe7f58170e967959a932c4f824 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 07a9b32eaae792ff7d0fcac14d8920c937c0a9c3 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 8b300f726640c48c3edfe9c453334dd801f4b74e 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 5e13d0a37666955b6cfddc0f73cb40ed645b8a05 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < f6c412dcfd76b0516d51aa847d8f4c7b70381b09 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 735ee8582da3d239eb0c7a53adca61b79fb228b3
Linux / Linux
All versions affected References
git.kernel.org: https://git.kernel.org/stable/c/f895191dc32c53eaf443b6443fe40945b2f92287 git.kernel.org: https://git.kernel.org/stable/c/cd5beda7e0e32865e214f28034bb92c1cecff885 git.kernel.org: https://git.kernel.org/stable/c/eaedc0bc18be46fe7f58170e967959a932c4f824 git.kernel.org: https://git.kernel.org/stable/c/07a9b32eaae792ff7d0fcac14d8920c937c0a9c3 git.kernel.org: https://git.kernel.org/stable/c/8b300f726640c48c3edfe9c453334dd801f4b74e git.kernel.org: https://git.kernel.org/stable/c/5e13d0a37666955b6cfddc0f73cb40ed645b8a05 git.kernel.org: https://git.kernel.org/stable/c/f6c412dcfd76b0516d51aa847d8f4c7b70381b09 git.kernel.org: https://git.kernel.org/stable/c/735ee8582da3d239eb0c7a53adca61b79fb228b3