{"schema_version":"1.7.5","id":"CVE-2026-43501","published":"2026-05-21T12:17:49.885Z","modified":"2026-07-25T03:56:36.216609538Z","related":["ALSA-2026:25191","ALSA-2026:25217","SUSE-SU-2026:22108-1","SUSE-SU-2026:22137-1","SUSE-SU-2026:22433-1","SUSE-SU-2026:22458-1","SUSE-SU-2026:22598-1","SUSE-SU-2026:22672-1","SUSE-SU-2026:22673-1","SUSE-SU-2026:22674-1","SUSE-SU-2026:22675-1","SUSE-SU-2026:22676-1","SUSE-SU-2026:22677-1","SUSE-SU-2026:22678-1","SUSE-SU-2026:22679-1","SUSE-SU-2026:22680-1","SUSE-SU-2026:22681-1","SUSE-SU-2026:22682-1","SUSE-SU-2026:22683-1","SUSE-SU-2026:22684-1","SUSE-SU-2026:22685-1","SUSE-SU-2026:22686-1","SUSE-SU-2026:22687-1","SUSE-SU-2026:22689-1","SUSE-SU-2026:22690-1","SUSE-SU-2026:22691-1","SUSE-SU-2026:22692-1","SUSE-SU-2026:22693-1","SUSE-SU-2026:22694-1","SUSE-SU-2026:22695-1","SUSE-SU-2026:22696-1","SUSE-SU-2026:22697-1","SUSE-SU-2026:22698-1","SUSE-SU-2026:22710-1","SUSE-SU-2026:22711-1","SUSE-SU-2026:22712-1","SUSE-SU-2026:22713-1","SUSE-SU-2026:22714-1","SUSE-SU-2026:22715-1","SUSE-SU-2026:22716-1","SUSE-SU-2026:22717-1","SUSE-SU-2026:22718-1","SUSE-SU-2026:22719-1","SUSE-SU-2026:22720-1","SUSE-SU-2026:22721-1","SUSE-SU-2026:22722-1","SUSE-SU-2026:22723-1","SUSE-SU-2026:22724-1","SUSE-SU-2026:22725-1","SUSE-SU-2026:22726-1","SUSE-SU-2026:22727-1","SUSE-SU-2026:22728-1","SUSE-SU-2026:22729-1","SUSE-SU-2026:22730-1","SUSE-SU-2026:22731-1","SUSE-SU-2026:22732-1","SUSE-SU-2026:22733-1","SUSE-SU-2026:22734-1","SUSE-SU-2026:22735-1","SUSE-SU-2026:22743-1","SUSE-SU-2026:22744-1","SUSE-SU-2026:22746-1","SUSE-SU-2026:22747-1","SUSE-SU-2026:22748-1","SUSE-SU-2026:22749-1","SUSE-SU-2026:22755-1","SUSE-SU-2026:22758-1","SUSE-SU-2026:22759-1","SUSE-SU-2026:22761-1","SUSE-SU-2026:22762-1","SUSE-SU-2026:22763-1","SUSE-SU-2026:22775-1","SUSE-SU-2026:22776-1","SUSE-SU-2026:22777-1","SUSE-SU-2026:22778-1","SUSE-SU-2026:22780-1","SUSE-SU-2026:22781-1","SUSE-SU-2026:22782-1","SUSE-SU-2026:22783-1","SUSE-SU-2026:22784-1","SUSE-SU-2026:22785-1","SUSE-SU-2026:22786-1","SUSE-SU-2026:2310-1","SUSE-SU-2026:2331-1","SUSE-SU-2026:2332-1","SUSE-SU-2026:2383-1","SUSE-SU-2026:2421-1","SUSE-SU-2026:2482-1","SUSE-SU-2026:2591-1","SUSE-SU-2026:2855-1","SUSE-SU-2026:2857-1","SUSE-SU-2026:2858-1","SUSE-SU-2026:2862-1","SUSE-SU-2026:2864-1","SUSE-SU-2026:2866-1","SUSE-SU-2026:2867-1","SUSE-SU-2026:2868-1","SUSE-SU-2026:2887-1","SUSE-SU-2026:2888-1","SUSE-SU-2026:2889-1","SUSE-SU-2026:2890-1","SUSE-SU-2026:2894-1","SUSE-SU-2026:2895-1","SUSE-SU-2026:2899-1","SUSE-SU-2026:2902-1","SUSE-SU-2026:2910-1","SUSE-SU-2026:2920-1","SUSE-SU-2026:2930-1","SUSE-SU-2026:2932-1","SUSE-SU-2026:2933-1","SUSE-SU-2026:2937-1","SUSE-SU-2026:2938-1","SUSE-SU-2026:2943-1","SUSE-SU-2026:2945-1","SUSE-SU-2026:2956-1","SUSE-SU-2026:2957-1","SUSE-SU-2026:2961-1","SUSE-SU-2026:2989-1","SUSE-SU-2026:2991-1","SUSE-SU-2026:2997-1","SUSE-SU-2026:3075-1","openSUSE-SU-2026:10859-1"],"summary":"ipv6: rpl: reserve mac_len headroom when recompressed SRH grows","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: rpl: reserve mac_len headroom when recompressed SRH grows\n\nipv6_rpl_srh_rcv() decompresses an RFC 6554 Source Routing Header, swaps\nthe next segment into ipv6_hdr->daddr, recompresses, then pulls the old\nheader and pushes the new one plus the IPv6 header back.  The\nrecompressed header can be larger than the received one when the swap\nreduces the common-prefix length the segments share with daddr (CmprI=0,\nCmprE>0, seg[0][0] != daddr[0] gives the maximum +8 bytes).\n\npskb_expand_head() was gated on segments_left == 0, so on earlier\nsegments the push consumed unchecked headroom.  Once skb_push() leaves\nfewer than skb->mac_len bytes in front of data,\nskb_mac_header_rebuild()'s call to:\n\n\tskb_set_mac_header(skb, -skb->mac_len);\n\nwill store (data - head) - mac_len into the u16 mac_header field, which\nwraps to ~65530, and the following memmove() writes mac_len bytes ~64KiB\npast skb->head.\n\nA single AF_INET6/SOCK_RAW/IPV6_HDRINCL packet over lo with a two\nsegment type-3 SRH (CmprI=0, CmprE=15) reaches headroom 8 after one\npass; KASAN reports a 14-byte OOB write in ipv6_rthdr_rcv.\n\nFix this by expanding the head whenever the remaining room is less than\nthe push size plus mac_len, and request that much extra so the rebuilt\nMAC header fits afterwards.","affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"8610c7c6e3bd647ff98d21c8bc0580e77bc2f8b3"},{"fixed":"bde199c72d319a4e207f88daabc888317504e2fb"},{"fixed":"be1fa0aa9b4fdd5a8b7a61ba520a690a68391e6e"},{"fixed":"0a9e8053f1f8a8e1bfc1dd61ffe67be6c1180402"},{"fixed":"8e8be63465a5e80394c70324603dfea1bfdad48f"},{"fixed":"4babc2d9fda2df43823b85d08a0180b68f1b0854"},{"fixed":"c261d07a80576dc8ccf394ef8f074f8c67a06b37"},{"fixed":"7398ebefbfd4f8a31d4f665a4213302fa995494b"},{"fixed":"9e6bf146b55999a095bb14f73a843942456d1adc"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-43501.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.7.0"},{"fixed":"5.10.258"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.11.0"},{"fixed":"5.15.209"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.16.0"},{"fixed":"6.1.175"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.2.0"},{"fixed":"6.6.140"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.7.0"},{"fixed":"6.12.86"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.18.27"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"7.0.4"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-43501.json"}}],"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/0a9e8053f1f8a8e1bfc1dd61ffe67be6c1180402"},{"type":"WEB","url":"https://git.kernel.org/stable/c/4babc2d9fda2df43823b85d08a0180b68f1b0854"},{"type":"WEB","url":"https://git.kernel.org/stable/c/7398ebefbfd4f8a31d4f665a4213302fa995494b"},{"type":"WEB","url":"https://git.kernel.org/stable/c/8e8be63465a5e80394c70324603dfea1bfdad48f"},{"type":"WEB","url":"https://git.kernel.org/stable/c/9e6bf146b55999a095bb14f73a843942456d1adc"},{"type":"WEB","url":"https://git.kernel.org/stable/c/bde199c72d319a4e207f88daabc888317504e2fb"},{"type":"WEB","url":"https://git.kernel.org/stable/c/be1fa0aa9b4fdd5a8b7a61ba520a690a68391e6e"},{"type":"WEB","url":"https://git.kernel.org/stable/c/c261d07a80576dc8ccf394ef8f074f8c67a06b37"},{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-43501.json"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:25191"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:25217"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:27713"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:27731"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:33900"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:34094"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:34095"},{"type":"ADVISORY","url":"https://access.redhat.com/security/cve/CVE-2026-43501"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/43xxx/CVE-2026-43501.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-43501"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2480457"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/43xxx/CVE-2026-43501.json"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}