CVE-2026-43190
Linux kernel netfilter xt_tcpmss: out-of-bounds read in TCP option parsing.
Is CVE-2026-43190 being exploited?
Not confirmed. CVE-2026-43190 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.46% probability of exploitation in the next 30 days.
How severe is CVE-2026-43190?
CVE-2026-43190 is rated High with a CVSS score of 8.2. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-43190?
Yes. A fix has been recorded for CVE-2026-43190. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-43190 affect?
CVE-2026-43190 affects Linux kernel (netfilter xt_tcpmss). Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-43190?
Update to patched kernel version
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Out-of-bounds read could disclose kernel memory or crash a host via crafted TCP options.
Patch when possible
- affected>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 and < f895191dc32c53eaf443b6443fe40945b2f92287
- affected>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 and < cd5beda7e0e32865e214f28034bb92c1cecff885
- affected>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 and < eaedc0bc18be46fe7f58170e967959a932c4f824
- affected>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 and < 07a9b32eaae792ff7d0fcac14d8920c937c0a9c3
- affected>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 and < 8b300f726640c48c3edfe9c453334dd801f4b74e
- affected>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 and < 5e13d0a37666955b6cfddc0f73cb40ed645b8a05
- affected>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 and < f6c412dcfd76b0516d51aa847d8f4c7b70381b09
- affected>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 and < 735ee8582da3d239eb0c7a53adca61b79fb228b3
- affected2.6.12
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.