CVE-2026-43057
7.5Linux · kernel
A checksum offload flaw in the Linux kernel network stack fails to properly handle tunneled traffic during IPv6 GSO fallback.
Executive summary
A network stack flaw in the Linux kernel allows unauthenticated remote attackers to trigger a denial of service via malformed tunneled IPv6 traffic.
Vulnerability
This is a denial of service vulnerability in the network subsystem, specifically affecting the handling of checksum offloads and GSO fallback for tunneled IPv6 packets with extension headers, triggerable by unauthenticated remote users.
Business impact
A successful exploitation of this vulnerability leads to system instability or complete service disruption via kernel panics or resource exhaustion. Because the flaw can be triggered remotely without authentication, internet facing servers are at significant risk of availability loss. The CVSS score of 7.5 reflects a high severity threat to operational continuity.
Remediation
Immediate Action: Update the Linux kernel to version 6.1.168, 6.6.134, 6.12.81, or later, depending on the active release branch.
Proactive Monitoring: Monitor network interface error rates and system logs for unexpected kernel crashes or performance degradation associated with network packet processing.
Compensating Controls: Deploy edge firewalls or network intrusion prevention systems to drop malformed IPv6 packets or unusual tunnel traffic patterns before they reach vulnerable hosts.
Exploitation status
Public Exploit Available: No (false / unknown)
Analyst recommendation
Administrators managing systems running affected Linux kernel branches must prioritize applying the latest stable kernel updates. Immediate patching is vital to prevent potential remote denial of service conditions that could disrupt critical infrastructure services.