CVE-2026-43057
Description
In the Linux kernel, the following vulnerability has been resolved: net: correctly handle tunneled traffic on IPV6_CSUM GSO fallback NETIF_F_IPV6_CSUM only advertises support for checksum offload of packets without IPv6 extension headers. Packets with extension headers must fall back onto software checksumming. Since TSO depends on checksum offload, those must revert to GSO. The below commit introduces that fallback. It always checks network header length. For tunneled packets, the inner header length must be checked instead. Extend the check accordingly. A special case is tunneled packets without inner IP protocol. Such as RFC 6951 SCTP in UDP. Those are not standard IPv6 followed by transport header either, so also must revert to the software GSO path.
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ if you've already worked around this in production โ publish your fix to the community-verified tier.
โ Propose a mitigation on Community โ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| sles | affected | | |
| debian | bookworm | fixed | 6.1.170-1 |
| debian | bullseye | fixed | 0 |
| debian | forky | fixed | 6.19.12-1 |
| debian | sid | fixed | 6.19.12-1 |
| debian | trixie | fixed | 6.12.85-1 |
| linux-kernel | affected | 6.1.168 | |
| linux-kernel | 6.17 | affected | |
| linux-kernel | 7.0 | affected | |
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| gcp | | |
References
- https://git.kernel.org/stable/c/2094a7cf91b71367b649f991aacc7b579f793d0b
- https://git.kernel.org/stable/c/33670f780e0120c3dacda188c512bbffe0b6044c
- https://git.kernel.org/stable/c/732fdeb2987c94b439d51f5cb9addddc2fc48c42
- https://git.kernel.org/stable/c/a98b78116a27e2a57b696b569b2cb431c95cf9b6
- https://git.kernel.org/stable/c/c4336a07eb6b2526dc2b62928b5104b41a7f81f5
- https://git.kernel.org/stable/c/ed71cf465c75f5688b07a35d373cd1d6b589c8ea
- https://www.suse.com/security/cve/CVE-2026-43057.html
- https://security-tracker.debian.org/tracker/CVE-2026-43057
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.