CVE-2026-43384 - Vulnerability Analysis
CriticalCVSS: 9.8Last Updated: May 11, 2026
Linux Kernel - Timing Attack
Published: May 8, 2026Updated: May 11, 2026Remote Exploitable
Overview
Linux kernel contains a timing attack vulnerability caused by non-constant-time MAC comparison in net/tcp-ao, letting attackers potentially infer MAC values via timing analysis, exploit requires network access.
Severity & Score
Severity: Critical
CVSS Score: 9.8
Impact
Attackers can perform timing attacks to infer MAC values, potentially compromising authentication integrity.
Mitigation
Update to the latest Linux kernel version with the MAC comparison fix.
References
Related Resources
Details
- CVE ID
- CVE-2026-43384
- Severity
- Critical
- CVSS Score
- 9.8
- Type
- undefined
- Status
- new
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H