CVE-2026-43198·Kernel vulnerability
In the Linux kernel, the following vulnerability has been resolved: tcp: fix potential race in tcp_v6_syn_recv_sock() Code in tcp_v6_syn_recv_sock() after the call to tcp_v4_syn_recv_sock() is done too late. After tcp_v4_syn_recv_sock(), the child socket is already visible from TCP ehash table and other cpus might use it. Since newinet->pinet6 is still pointing to the listener ipv6_pinfo bad things can happen as syzbot found. Move the problematic code in tcp_v6_mapped_child_init() and call this new helper from tcp_v4_syn_recv_sock() before the ehash insertion. This allows the removal of one tcp_sync_mss(), since tcp_v4_syn_recv_sock() will call it with the correct context.
- Severity
- critical
- Software
- Kernel
- Fixed in
- 6.19.6
- Published
- 2026-05-06
Affected versions
From: 6.19
Until: 6.19.6
Fixed in: 6.19.6
How to fix this CVE
Update your Linux kernel to version 6.19.6 or later to resolve a critical race condition in TCP IPv6 socket initialization that could allow remote attackers to trigger memory corruption. This patch reorganizes socket initialization code to prevent concurrent access to uninitialized IPv6 structures during connection establishment. Kernel updates typically require a system reboot to take effect.
sudo dnf check-update kernel && sudo dnf update kernel && sudo rebootDefensia detects this vulnerability
How to check if you are affected
- Check your kernel version: uname -r
- Verify if vulnerable version is installed: grep -i '6.19' /proc/version || echo 'Not vulnerable to this range'
- List loaded kernel modules related to TCP: lsmod | grep -E 'tcp|ipv6'
- After patching, confirm new kernel version: uname -r (should be 6.19.6 or later)
- Verify kernel update completed successfully: dmesg | tail -20 (should show new kernel boot messages)
FAQ
What is CVE-2026-43198?
CVE-2026-43198 is a critical race condition in the Linux kernel's TCP IPv6 implementation that occurs when a child socket becomes visible to other CPUs before its IPv6-specific fields are properly initialized, potentially leading to memory corruption and system crashes.
Is CVE-2026-43198 being actively exploited?
No, this vulnerability is not currently listed on the CISA Known Exploited Vulnerabilities (KEV) catalog and no public exploits are known to be available, though the critical CVSS score of 9.8 indicates high severity if exploited.
What versions of Kernel are affected by CVE-2026-43198?
Linux kernel versions 6.19 through 6.19.6 (inclusive) are affected; kernel 6.19.6 and all later versions contain the fix.
How do I check if my server is vulnerable to CVE-2026-43198?
Run 'uname -r' and compare your kernel version to the affected range (6.19 to 6.19.6); if your version falls within this range, your system is vulnerable and requires a kernel update.
Does Defensia detect CVE-2026-43198?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If Linux kernel is installed on a monitored server running versions 6.19 through 6.19.6, CVE-2026-43198 will appear in your dashboard with remediation steps.
Related Kernel CVEs
References
- https://git.kernel.org/stable/c/7178e2a8027423b2af17ab95df73a749a5b72e5b
- https://git.kernel.org/stable/c/858d2a4f67ff69e645a43487ef7ea7f28f06deae
- https://git.kernel.org/stable/c/9ed654e340f4c73bc6f0af2fbc90ac293e645ce0
- https://git.kernel.org/stable/c/a7e761ba55efaa9c49e0afdd304bb78167af3429
- https://git.kernel.org/stable/c/aef4a9ae95d1bc4f7897065011e6261026719aeb
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2026-43198. Free for 1 server.
Get started free