LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2026-43384

CVE-2026-43384 - Vulnerability Analysis

CriticalCVSS: 9.8

Last Updated: May 11, 2026

Linux Kernel - Timing Attack

Published: May 8, 2026Updated: May 11, 2026Remote Exploitable

Overview

Linux kernel contains a timing attack vulnerability caused by non-constant-time MAC comparison in net/tcp-ao, letting attackers potentially infer MAC values via timing analysis, exploit requires network access.

Severity & Score

Severity: Critical
CVSS Score: 9.8

Impact

Attackers can perform timing attacks to infer MAC values, potentially compromising authentication integrity.

Mitigation

Update to the latest Linux kernel version with the MAC comparison fix.

Details

CVE ID
CVE-2026-43384
Severity
Critical
CVSS Score
9.8
Type
undefined
Status
new

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H