Affects Linux kernel, core infrastructure used across industries; could allow remote code execution on many systems.
CVE-2026-43037
Linux kernel IPv4/IPv6 IP options handling flaw enables attacker data copy, enabling RCE.
Is CVE-2026-43037 being exploited?
Not confirmed. CVE-2026-43037 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.56% probability of exploitation in the next 30 days.
How severe is CVE-2026-43037?
CVE-2026-43037 is rated Critical with a CVSS score of 9.8. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-43037?
Yes. A fix has been recorded for CVE-2026-43037. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-43037 affect?
CVE-2026-43037 affects Linux kernel. Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-43037?
Update kernel to patched version; reboot as needed.
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Attacker-controlled data in IP options may overflow fixed kernel buffer, enabling remote code execution.
Immediate action required
- affected>= c4d3efafcc933fd2ffd169d7dc4f980393a13796 and < ea9f65b27c8404e164848ebff1443310fd187629
- affected>= c4d3efafcc933fd2ffd169d7dc4f980393a13796 and < d6621f60192fe10c047a4487be42a6f4c150707f
- affected>= c4d3efafcc933fd2ffd169d7dc4f980393a13796 and < 2cc6e3b0fe0f0242d1f530a93a4924f48ab85ba5
- affected>= c4d3efafcc933fd2ffd169d7dc4f980393a13796 and < a0c4ce9900a108eaf55d0f3b399cb55999647d39
- affected>= c4d3efafcc933fd2ffd169d7dc4f980393a13796 and < 1063515ce15ff31065c4e7f8265f4c2fd3c54876
- affected>= c4d3efafcc933fd2ffd169d7dc4f980393a13796 and < 590f622669b97eaf7b57a1de7b0a6e68c5d8b2c3
- affected>= c4d3efafcc933fd2ffd169d7dc4f980393a13796 and < 4a622658f384b03560834cbe8ffcfe69a278f7c8
- affected>= c4d3efafcc933fd2ffd169d7dc4f980393a13796 and < 2edfa31769a4add828a7e604b21cb82aaaa05925
- affected2.6.22
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.