LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2026-43383

CVE-2026-43383 - Vulnerability Analysis

CriticalCVSS: 9.4

Last Updated: May 11, 2026

Linux Kernel - Timing Attack

Published: May 8, 2026Updated: May 11, 2026Remote Exploitable

Overview

Linux kernel contains a timing attack vulnerability caused by non-constant-time MAC comparison in net/tcp-md5, letting attackers potentially infer MAC values, exploit requires network access to trigger timing measurement.

Severity & Score

Severity: Critical
CVSS Score: 9.4

Impact

Attackers can perform timing attacks to infer MAC values, potentially compromising authentication integrity.

Mitigation

Update to the latest Linux kernel version with the fix for constant-time MAC comparison.

Details

CVE ID
CVE-2026-43383
Severity
Critical
CVSS Score
9.4
Type
undefined
Status
new

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H