Back to overview

CVE-2026-43384

CRITICAL
9.8
CVSS 3.1
Description
In the Linux kernel, the following vulnerability has been resolved: net/tcp-ao: Fix MAC comparison to be constant-time To prevent timing attacks, MACs need to be compared in constant time. Use the appropriate helper function for this.

Metadata

CVE ID
CVE-2026-43384
State
PUBLISHED
Assigner
Linux
Reserved
2026-05-01 14:12 UTC
Published
2026-05-08 14:21 UTC
Last updated
2026-05-11 22:23 UTC
Vendor / Product
Linux / Linux
Sources
cve.org  ·  NVD

Severity & Metrics

9.8 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products (2)
VendorProductPlatformVersions
Linux Linux 0a3a809089eb1d4a0a2fd0c16b520d603988c859 < 8be6ed64966da48b6c4726918f106c18742a5125, 0a3a809089eb1d4a0a2fd0c16b520d603988c859 < a269cbdc442f8658bca35383e34b9d0b0ff95a1c, 0a3a809089eb1d4a0a2fd0c16b520d603988c859 < 080b0e210088296dd50d6637c06c1db14246adfe, 0a3a809089eb1d4a0a2fd0c16b520d603988c859 < 67edfec516d30d3e62925c397be4a1e5185802fc
Linux Linux 6.7, 0 < 6.7, 6.12.78 ≤ 6.12.*, 6.18.19 ≤ 6.18.* …
CVSS scores (1)
ScoreSeverityVersionSourceVector
9.8 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Back to overview