🛡️ CVE-2026-43194 on Ubuntu — linux
Description
In the Linux kernel, the following vulnerability has been resolved: net: consume xmit errors of GSO frames udpgro_frglist.sh and udpgro_bench.sh are the flakiest tests currently in NIPA. They fail in the same exact way, TCP GRO test stalls occasionally and the test gets killed after 10min. These tests use veth to simulate GRO. They attach a trivial ("return XDP_PASS;") XDP program to the veth to force TSO off and NAPI on. Digging into the failure mode we can see that the connection is completely stuck after a burst of drops. The sender's snd_nxt is at sequence number N [1], but the receiver claims to have received (rcv_nxt) up to N + 3 * MSS [2]. Last piece of the puzzle is that senders rtx queue is not empty (let's say the block in the rtx queue is at sequence number N - 4 * MSS [3]). In this state, sender sends a retransmission from the rtx queue with a single segment, and sequence numbers N-4*MSS:N-3*MSS [3]. Receiver sees it and responds with an ACK all the way up to N + 3 * MSS [2]. But sender will reject this ack as TCP_ACK_UNSENT_DATA because it has no recollection of ever sending data that far out [1]. And we are stuck. The root cause is the mess of the xmit return codes. veth returns an error when it can't xmit a frame. We end up with a loss event like this: ------------------------------------------------- | GSO super frame 1 | GSO super frame 2 | |-----------------------------------------------| | seg | seg | seg | seg | seg | seg | seg | seg | | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | ------------------------------------------------- x ok ok <ok>| ok ok ok <x> \\ snd_nxt "x" means packet lost by veth, and "ok" means it went thru. Since veth has TSO disabled in this test it sees individual segments. Segment 1 is on the retransmit queue and will be resent. So why did the sender not advance snd_nxt even tho it clearly did send up to seg 8? tcp_write_xmit() interprets the return code from the core to mean that data has not been sent at all. Since TCP deals with GSO super frames, not individual segment the crux of the problem is that loss of a single segment can be interpreted as loss of all. TCP only sees the last return code for the last segment of the GSO frame (in <> brackets in the diagram above). Of course for the problem to occur we need a setup or a device without a Qdisc. Otherwise Qdisc layer disconnects the protocol layer from the device errors completely. We have multiple ways to fix this. 1) make veth not return an error when it lost a packet. While this is what I think we did in the past, the issue keeps reappearing and it's annoying to debug. The game of whack a mole is not great. 2) fix the damn return codes We only talk about NETDEV_TX_OK and NETDEV_TX_BUSY in the documentation, so maybe we should make the return code from ndo_start_xmit() a boolean. I like that the most, but perhaps some ancient, not-really-networking protocol would suffer. 3) make TCP ignore the errors It is not entirely clear to me what benefit TCP gets from interpreting the result of ip_queue_xmit()? Specifically once the connection is established and we're pushing data - packet loss is just packet loss? 4) this fix Ignore the rc in the Qdisc-less+GSO case, since it's unreliable. We already always return OK in the TCQ_F_CAN_BYPASS case. In the Qdisc-less case let's be a bit more conservative and only mask the GSO errors. This path is taken by non-IP-"networks" like CAN, MCTP etc, so we could regress some ancient thing. This is the simplest, but also maybe the hackiest fix? Similar fix has been proposed by Eric in the past but never committed because original reporter was working with an OOT driver and wasn't providing feedback (see Link).
Distribution advisory
This page covers CVE-2026-43194 as tracked by Ubuntu, for the package linux. The fix is available in version 5.15.0-1112.119~20.04.1; earlier versions remain affected.
How this vulnerability can be exploited
This issue can be reached over the network, attack complexity is low, an attacker needs no privileges on the target. No user interaction is required. The scope is unchanged, so the impact stays within the vulnerable component. Rated impact: confidentiality none, integrity none, availability high.
Affected software
UBUNTU-CVE-2026-43194 is recorded against 158 packages.
- linux
- linux-allwinner-5.19
- linux-aws
- linux-aws-5.0
- linux-aws-5.11
- linux-aws-5.13
- linux-aws-5.15 (fixed in 5.15.0-1112.119~20.04.1)
- linux-aws-5.19
- linux-aws-5.3
- linux-aws-5.4
- linux-aws-5.8
- linux-aws-6.14
- linux-aws-6.17
- linux-aws-6.2
- linux-aws-6.5
- linux-aws-6.8 (fixed in 6.8.0-1060.63~22.04.1)
- linux-aws-fips (fixed in 6.8.0-1060.63+fips1)
- linux-aws-hwe
- linux-azure
- linux-azure-4.15
- linux-azure-5.11
- linux-azure-5.13
- linux-azure-5.15 (fixed in 5.15.0-1117.126~20.04.1)
- linux-azure-5.19
Show the remaining 134 packages
- linux-azure-5.3
- linux-azure-5.4
- linux-azure-5.8
- linux-azure-6.11
- linux-azure-6.14
- linux-azure-6.17
- linux-azure-6.2
- linux-azure-6.5
- linux-azure-6.8 (fixed in 6.8.0-1063.71~22.04.1)
- linux-azure-edge
- linux-azure-fde
- linux-azure-fde-5.15 (fixed in 5.15.0-1117.126~20.04.2)
- linux-azure-fde-5.19
- linux-azure-fde-6.14
- linux-azure-fde-6.17
- linux-azure-fde-6.2
- linux-azure-fde-6.8 (fixed in 6.8.0-1062.69~22.04.1)
- linux-azure-fips (fixed in 6.8.0-1062.69+fips1)
- linux-azure-nvidia
- linux-azure-nvidia-6.14
- linux-bluefield
- linux-fips (fixed in 6.8.0-134.134+fips1)
- linux-gcp
- linux-gcp-4.15
- linux-gcp-5.11
- linux-gcp-5.13
- linux-gcp-5.15
- linux-gcp-5.19
- linux-gcp-5.3
- linux-gcp-5.4
- linux-gcp-5.8
- linux-gcp-6.11
- linux-gcp-6.14
- linux-gcp-6.17
- linux-gcp-6.2
- linux-gcp-6.5
- linux-gcp-6.8 (fixed in 6.8.0-1063.69~22.04.1)
- linux-gcp-fips (fixed in 6.8.0-1063.69+fips1)
- linux-gke (fixed in 6.8.0-1058.64)
- linux-gke-4.15
- linux-gke-5.15
- linux-gke-5.4
- linux-gkeop (fixed in 6.8.0-1045.48)
- linux-gkeop-5.15
- linux-gkeop-5.4
- linux-hwe
- linux-hwe-5.11
- linux-hwe-5.13
- linux-hwe-5.15 (fixed in 5.15.0-186.196~20.04.1)
- linux-hwe-5.19
- linux-hwe-5.4
- linux-hwe-5.8
- linux-hwe-6.11
- linux-hwe-6.14
- linux-hwe-6.17
- linux-hwe-6.2
- linux-hwe-6.5
- linux-hwe-6.8 (fixed in 6.8.0-136.136~22.04.1)
- linux-hwe-edge
- linux-ibm (fixed in 6.8.0-1060.61)
- linux-ibm-5.15 (fixed in 5.15.0-1106.110~20.04.1)
- linux-ibm-5.4
- linux-ibm-6.8 (fixed in 6.8.0-1060.61~22.04.1)
- linux-intel-5.13
- linux-intel-iot-realtime (fixed in 5.15.0-1104.106)
- linux-intel-iotg (fixed in 5.15.0-1107.113)
- linux-intel-iotg-5.15 (fixed in 5.15.0-1107.113~20.04.1)
- linux-iot
- linux-kvm (fixed in 5.15.0-1104.109)
- linux-lowlatency (fixed in 6.8.0-134.134.1)
- linux-lowlatency-hwe-5.15 (fixed in 5.15.0-184.194~20.04.1)
- linux-lowlatency-hwe-5.19
- linux-lowlatency-hwe-6.11
- linux-lowlatency-hwe-6.2
- linux-lowlatency-hwe-6.5
- linux-lowlatency-hwe-6.8 (fixed in 6.8.0-134.134.1~22.04.1)
- linux-lts-xenial
- linux-nvidia (fixed in 6.8.0-1058.61)
- linux-nvidia-6.11
- linux-nvidia-6.17
- linux-nvidia-6.2
- linux-nvidia-6.5
- linux-nvidia-6.8 (fixed in 6.8.0-1058.61~22.04.1)
- linux-nvidia-lowlatency (fixed in 6.8.0-1058.61.1)
- linux-nvidia-tegra (fixed in 6.8.0-1029.30)
- linux-nvidia-tegra-5.15 (fixed in 5.15.0-1064.66~20.04.1)
- linux-nvidia-tegra-igx (fixed in 5.15.0-1053.53)
- linux-oem
- linux-oem-5.10
- linux-oem-5.13
- linux-oem-5.14
- linux-oem-5.17
- linux-oem-5.6
- linux-oem-6.0
- linux-oem-6.1
- linux-oem-6.11
- linux-oem-6.14
- linux-oem-6.17
- linux-oem-6.5
- linux-oem-6.8
- linux-oracle
- linux-oracle-5.0
- linux-oracle-5.11
- linux-oracle-5.13
- linux-oracle-5.15 (fixed in 5.15.0-1109.115~20.04.1)
- linux-oracle-5.3
- linux-oracle-5.4
- linux-oracle-5.8
- linux-oracle-6.14
- linux-oracle-6.17
- linux-oracle-6.5
- linux-oracle-6.8 (fixed in 6.8.0-1057.58~22.04.1)
- linux-raspi
- linux-raspi-5.4
- linux-raspi-realtime (fixed in 6.8.0-2049.50)
- linux-raspi2
- linux-realtime
- linux-realtime-6.14
- linux-realtime-6.17
- linux-realtime-6.8 (fixed in 6.8.1-1055.56~22.04.1)
- linux-riscv
- linux-riscv-5.11
- linux-riscv-5.15 (fixed in 5.15.0-1106.110~20.04.1)
- linux-riscv-5.19
- linux-riscv-5.8
- linux-riscv-6.14
- linux-riscv-6.17
- linux-riscv-6.5
- linux-riscv-6.8 (fixed in 6.8.0-134.134~22.04.1)
- linux-starfive-5.19
- linux-starfive-6.2
- linux-starfive-6.5
- linux-xilinx (fixed in 6.8.0-1032.33)
- linux-xilinx-zynqmp (fixed in 5.15.0-1075.79)
Timeline and source
Published on 6 May 2026 and last revised on 11 August 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.
References
ubuntu.com (Report)
www.cve.org (Report)
git.kernel.org (Report)
ubuntu.com (Advisory)
ubuntu.com (Advisory)
ubuntu.com (Advisory)
ubuntu.com (Advisory)
ubuntu.com (Advisory)
ubuntu.com (Advisory)
ubuntu.com (Advisory)
ubuntu.com (Advisory)
ubuntu.com (Advisory)
ubuntu.com (Advisory)
ubuntu.com (Advisory)
ubuntu.com (Advisory)
CVE-2026-43194 on other distributions
Each distribution ships its own build and its own fixed version. Pick the one you run:
Details
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Packages
| Software | From version | Fixed in |
|---|---|---|
| linux | — | — |
| linux-allwinner-5.19 | — | — |
| linux-aws | — | — |
| linux-aws-5.0 | — | — |
| linux-aws-5.11 | — | — |
| linux-aws-5.13 | — | — |
| linux-aws-5.15 | — | 5.15.0-1112.119~20.04.1 |
| linux-aws-5.19 | — | — |
| linux-aws-5.3 | — | — |
| linux-aws-5.4 | — | — |
| linux-aws-5.8 | — | — |
| linux-aws-6.14 | — | — |
| linux-aws-6.17 | — | — |
| linux-aws-6.2 | — | — |
| linux-aws-6.5 | — | — |
| linux-aws-6.8 | — | 6.8.0-1060.63~22.04.1 |
| linux-aws-fips | — | 6.8.0-1060.63+fips1 |
| linux-aws-hwe | — | — |
| linux-azure | — | — |
| linux-azure-4.15 | — | — |
| linux-azure-5.11 | — | — |
| linux-azure-5.13 | — | — |
| linux-azure-5.15 | — | 5.15.0-1117.126~20.04.1 |
| linux-azure-5.19 | — | — |
| linux-azure-5.3 | — | — |
| linux-azure-5.4 | — | — |
| linux-azure-5.8 | — | — |
| linux-azure-6.11 | — | — |
| linux-azure-6.14 | — | — |
| linux-azure-6.17 | — | — |
| linux-azure-6.2 | — | — |
| linux-azure-6.5 | — | — |
| linux-azure-6.8 | — | 6.8.0-1063.71~22.04.1 |
| linux-azure-edge | — | — |
| linux-azure-fde | — | — |
| linux-azure-fde-5.15 | — | 5.15.0-1117.126~20.04.2 |
| linux-azure-fde-5.19 | — | — |
| linux-azure-fde-6.14 | — | — |
| linux-azure-fde-6.17 | — | — |
| linux-azure-fde-6.2 | — | — |
| linux-azure-fde-6.8 | — | 6.8.0-1062.69~22.04.1 |
| linux-azure-fips | — | 6.8.0-1062.69+fips1 |
| linux-azure-nvidia | — | — |
| linux-azure-nvidia-6.14 | — | — |
| linux-bluefield | — | — |
| linux-fips | — | 6.8.0-134.134+fips1 |
| linux-gcp | — | — |
| linux-gcp-4.15 | — | — |
| linux-gcp-5.11 | — | — |
| linux-gcp-5.13 | — | — |
| linux-gcp-5.15 | — | — |
| linux-gcp-5.19 | — | — |
| linux-gcp-5.3 | — | — |
| linux-gcp-5.4 | — | — |
| linux-gcp-5.8 | — | — |
| linux-gcp-6.11 | — | — |
| linux-gcp-6.14 | — | — |
| linux-gcp-6.17 | — | — |
| linux-gcp-6.2 | — | — |
| linux-gcp-6.5 | — | — |
| linux-gcp-6.8 | — | 6.8.0-1063.69~22.04.1 |
| linux-gcp-fips | — | 6.8.0-1063.69+fips1 |
| linux-gke | — | 6.8.0-1058.64 |
| linux-gke-4.15 | — | — |
| linux-gke-5.15 | — | — |
| linux-gke-5.4 | — | — |
| linux-gkeop | — | 6.8.0-1045.48 |
| linux-gkeop-5.15 | — | — |
| linux-gkeop-5.4 | — | — |
| linux-hwe | — | — |
| linux-hwe-5.11 | — | — |
| linux-hwe-5.13 | — | — |
| linux-hwe-5.15 | — | 5.15.0-186.196~20.04.1 |
| linux-hwe-5.19 | — | — |
| linux-hwe-5.4 | — | — |
| linux-hwe-5.8 | — | — |
| linux-hwe-6.11 | — | — |
| linux-hwe-6.14 | — | — |
| linux-hwe-6.17 | — | — |
| linux-hwe-6.2 | — | — |
| linux-hwe-6.5 | — | — |
| linux-hwe-6.8 | — | 6.8.0-136.136~22.04.1 |
| linux-hwe-edge | — | — |
| linux-ibm | — | 6.8.0-1060.61 |
| linux-ibm-5.15 | — | 5.15.0-1106.110~20.04.1 |
| linux-ibm-5.4 | — | — |
| linux-ibm-6.8 | — | 6.8.0-1060.61~22.04.1 |
| linux-intel-5.13 | — | — |
| linux-intel-iot-realtime | — | 5.15.0-1104.106 |
| linux-intel-iotg | — | 5.15.0-1107.113 |
| linux-intel-iotg-5.15 | — | 5.15.0-1107.113~20.04.1 |
| linux-iot | — | — |
| linux-kvm | — | 5.15.0-1104.109 |
| linux-lowlatency | — | 6.8.0-134.134.1 |
| linux-lowlatency-hwe-5.15 | — | 5.15.0-184.194~20.04.1 |
| linux-lowlatency-hwe-5.19 | — | — |
| linux-lowlatency-hwe-6.11 | — | — |
| linux-lowlatency-hwe-6.2 | — | — |
| linux-lowlatency-hwe-6.5 | — | — |
| linux-lowlatency-hwe-6.8 | — | 6.8.0-134.134.1~22.04.1 |
| linux-lts-xenial | — | — |
| linux-nvidia | — | 6.8.0-1058.61 |
| linux-nvidia-6.11 | — | — |
| linux-nvidia-6.17 | — | — |
| linux-nvidia-6.2 | — | — |
| linux-nvidia-6.5 | — | — |
| linux-nvidia-6.8 | — | 6.8.0-1058.61~22.04.1 |
| linux-nvidia-lowlatency | — | 6.8.0-1058.61.1 |
| linux-nvidia-tegra | — | 6.8.0-1029.30 |
| linux-nvidia-tegra-5.15 | — | 5.15.0-1064.66~20.04.1 |
| linux-nvidia-tegra-igx | — | 5.15.0-1053.53 |
| linux-oem | — | — |
| linux-oem-5.10 | — | — |
| linux-oem-5.13 | — | — |
| linux-oem-5.14 | — | — |
| linux-oem-5.17 | — | — |
| linux-oem-5.6 | — | — |
| linux-oem-6.0 | — | — |
| linux-oem-6.1 | — | — |
| linux-oem-6.11 | — | — |
| linux-oem-6.14 | — | — |
| linux-oem-6.17 | — | — |
| linux-oem-6.5 | — | — |
| linux-oem-6.8 | — | — |
| linux-oracle | — | — |
| linux-oracle-5.0 | — | — |
| linux-oracle-5.11 | — | — |
| linux-oracle-5.13 | — | — |
| linux-oracle-5.15 | — | 5.15.0-1109.115~20.04.1 |
| linux-oracle-5.3 | — | — |
| linux-oracle-5.4 | — | — |
| linux-oracle-5.8 | — | — |
| linux-oracle-6.14 | — | — |
| linux-oracle-6.17 | — | — |
| linux-oracle-6.5 | — | — |
| linux-oracle-6.8 | — | 6.8.0-1057.58~22.04.1 |
| linux-raspi | — | — |
| linux-raspi-5.4 | — | — |
| linux-raspi-realtime | — | 6.8.0-2049.50 |
| linux-raspi2 | — | — |
| linux-realtime | — | — |
| linux-realtime-6.14 | — | — |
| linux-realtime-6.17 | — | — |
| linux-realtime-6.8 | — | 6.8.1-1055.56~22.04.1 |
| linux-riscv | — | — |
| linux-riscv-5.11 | — | — |
| linux-riscv-5.15 | — | 5.15.0-1106.110~20.04.1 |
| linux-riscv-5.19 | — | — |
| linux-riscv-5.8 | — | — |
| linux-riscv-6.14 | — | — |
| linux-riscv-6.17 | — | — |
| linux-riscv-6.5 | — | — |
| linux-riscv-6.8 | — | 6.8.0-134.134~22.04.1 |
| linux-starfive-5.19 | — | — |
| linux-starfive-6.2 | — | — |
| linux-starfive-6.5 | — | — |
| linux-xilinx | — | 6.8.0-1032.33 |
| linux-xilinx-zynqmp | — | 5.15.0-1075.79 |
References
Similar Threats
- Unknown CGA-23jx-hhcx-m389
- Unknown CGA-2qp7-6757-fmgc
- Unknown CGA-2rj5-jc55-r267
- Unknown CGA-3m96-cwq8-6xmx
- Unknown CGA-3qj9-973w-fh9g
More UBUNTU CVE 2026 advisories
Browse all of UBUNTU CVE 2026 in the advisory index.
- UBUNTU-CVE-2026-43186
- UBUNTU-CVE-2026-43187
- UBUNTU-CVE-2026-43188
- UBUNTU-CVE-2026-43189
- UBUNTU-CVE-2026-43190
- UBUNTU-CVE-2026-43191
- UBUNTU-CVE-2026-43192
- UBUNTU-CVE-2026-43193
- UBUNTU-CVE-2026-43195
- UBUNTU-CVE-2026-43196
- UBUNTU-CVE-2026-43197
- UBUNTU-CVE-2026-43198
- UBUNTU-CVE-2026-43199
- UBUNTU-CVE-2026-43200
- UBUNTU-CVE-2026-43201
- UBUNTU-CVE-2026-43202
Site Security Check
Is linux part of your stack?
UBUNTU-CVE-2026-43194 is rated CVSS 7.5 High. BotEraser scans your installation against known CVE records and tells you whether this vulnerability applies to the versions you actually run.
Scan My Site Free →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.