# CVE-2026-43198

## Summary

- **CVE ID:** CVE-2026-43198
- **Severity:** CRITICAL
- **CVSS Score:** 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- **CWE:** N/A
- **Published:** May 6, 2026
- **Last Modified:** Sep 14, 2026

## Description

In the Linux kernel, the following vulnerability has been resolved:

tcp: fix potential race in tcp_v6_syn_recv_sock()

Code in tcp_v6_syn_recv_sock() after the call to tcp_v4_syn_recv_sock()
is done too late.

After tcp_v4_syn_recv_sock(), the child socket is already visible
from TCP ehash table and other cpus might use it.

Since newinet->pinet6 is still pointing to the listener ipv6_pinfo
bad things can happen as syzbot found.

Move the problematic code in tcp_v6_mapped_child_init()
and call this new helper from tcp_v4_syn_recv_sock() before
the ehash insertion.

This allows the removal of one tcp_sync_mss(), since
tcp_v4_syn_recv_sock() will call it with the correct
context.

## Affected Products

- Linux — Linux (1da177e4c3f41524e886b7f1b8a0c1fc7321cac2)
- Linux — Linux (2.6.12)
- Linux — Linux (0)
- Linux — Linux (6.18.16)
- Linux — Linux (6.19.6)
- Linux — Linux (7.0)
- Linux — Linux (5.10.270)
- Linux — Linux (5.15.221)
- Linux — Linux (6.1.188)
- Linux — Linux (6.6.157)
- Linux — Linux (6.12.110)

## References

- [CNA](https://git.kernel.org/stable/c/fe89b2f05b854847784f91127319172945c1fadd)
- [CNA](https://git.kernel.org/stable/c/7178e2a8027423b2af17ab95df73a749a5b72e5b)
- [CNA](https://git.kernel.org/stable/c/858d2a4f67ff69e645a43487ef7ea7f28f06deae)
- [redhat-SADP](https://access.redhat.com/security/cve/CVE-2026-43198)
- [redhat-SADP](https://bugzilla.redhat.com/show_bug.cgi?id=2467228)
- [redhat-SADP](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-43198.json)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:33215)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:30129)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:33285)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:34443)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:34094)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:35863)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:36216)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:36073)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:36349)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:35896)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:35894)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:36348)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:35904)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:41236)
- [CNA](https://git.kernel.org/stable/c/aef4a9ae95d1bc4f7897065011e6261026719aeb)
- [CNA](https://git.kernel.org/stable/c/dad1fe7db6c6519138430ac8f5e589c18f83bfc9)
- [CNA](https://git.kernel.org/stable/c/a7e761ba55efaa9c49e0afdd304bb78167af3429)
- [CNA](https://git.kernel.org/stable/c/cd644e6dc72eec8d9d988717ea1c54f8668ded69)
- [CNA](https://git.kernel.org/stable/c/9ed654e340f4c73bc6f0af2fbc90ac293e645ce0)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.30%
- **EPSS Percentile:** 22.5

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-17._