CVE-2026-43383 (GCVE-0-2026-43383)
Vulnerability from cvelistv5
Published
2026-05-08 14:21
Modified
2026-08-05 12:27
Severity ?
Summary
In the Linux kernel, the following vulnerability has been resolved: net/tcp-md5: Fix MAC comparison to be constant-time To prevent timing attacks, MACs need to be compared in constant time. Use the appropriate helper function for this.
Impacted products
Vendor Product Version
Linux Linux Version: cfb6eeb4c860592edd123fdea908d23c6ad1c7dc
Version: cfb6eeb4c860592edd123fdea908d23c6ad1c7dc
Version: cfb6eeb4c860592edd123fdea908d23c6ad1c7dc
Version: cfb6eeb4c860592edd123fdea908d23c6ad1c7dc
Version: cfb6eeb4c860592edd123fdea908d23c6ad1c7dc
Version: cfb6eeb4c860592edd123fdea908d23c6ad1c7dc
Version: cfb6eeb4c860592edd123fdea908d23c6ad1c7dc
Version: cfb6eeb4c860592edd123fdea908d23c6ad1c7dc
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "net/ipv4/Kconfig",
            "net/ipv4/tcp.c",
            "net/ipv4/tcp_ipv4.c",
            "net/ipv6/tcp_ipv6.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "821c8751fdeecdeecabeb11704dd33439c9e4bbc",
              "status": "affected",
              "version": "cfb6eeb4c860592edd123fdea908d23c6ad1c7dc",
              "versionType": "git"
            },
            {
              "lessThan": "ff44ec94d4fc8348600a69de0a8fa1102c23bce8",
              "status": "affected",
              "version": "cfb6eeb4c860592edd123fdea908d23c6ad1c7dc",
              "versionType": "git"
            },
            {
              "lessThan": "345a9530756528d7ca407663d659c3c40e75c3dd",
              "status": "affected",
              "version": "cfb6eeb4c860592edd123fdea908d23c6ad1c7dc",
              "versionType": "git"
            },
            {
              "lessThan": "5d305a95130a8d08b9545e47f1e18d29d59866cb",
              "status": "affected",
              "version": "cfb6eeb4c860592edd123fdea908d23c6ad1c7dc",
              "versionType": "git"
            },
            {
              "lessThan": "02669e2a4d207068edce7e8b5fafd85822018ce6",
              "status": "affected",
              "version": "cfb6eeb4c860592edd123fdea908d23c6ad1c7dc",
              "versionType": "git"
            },
            {
              "lessThan": "ae3831b44f477de048287493e184fc3ff913b624",
              "status": "affected",
              "version": "cfb6eeb4c860592edd123fdea908d23c6ad1c7dc",
              "versionType": "git"
            },
            {
              "lessThan": "b502e97e29d791ff7a8051f29a414535739be218",
              "status": "affected",
              "version": "cfb6eeb4c860592edd123fdea908d23c6ad1c7dc",
              "versionType": "git"
            },
            {
              "lessThan": "46d0d6f50dab706637f4c18a470aac20a21900d3",
              "status": "affected",
              "version": "cfb6eeb4c860592edd123fdea908d23c6ad1c7dc",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "net/ipv4/Kconfig",
            "net/ipv4/tcp.c",
            "net/ipv4/tcp_ipv4.c",
            "net/ipv6/tcp_ipv6.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "2.6.20"
            },
            {
              "lessThan": "2.6.20",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.10.*",
              "status": "unaffected",
              "version": "5.10.253",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.15.*",
              "status": "unaffected",
              "version": "5.15.210",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.1.*",
              "status": "unaffected",
              "version": "6.1.167",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.130",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.12.*",
              "status": "unaffected",
              "version": "6.12.78",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.18.*",
              "status": "unaffected",
              "version": "6.18.19",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.19.*",
              "status": "unaffected",
              "version": "6.19.9",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "7.0",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.10.253",
                  "versionStartIncluding": "2.6.20",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.15.210",
                  "versionStartIncluding": "2.6.20",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.1.167",
                  "versionStartIncluding": "2.6.20",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.130",
                  "versionStartIncluding": "2.6.20",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.12.78",
                  "versionStartIncluding": "2.6.20",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.18.19",
                  "versionStartIncluding": "2.6.20",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.19.9",
                  "versionStartIncluding": "2.6.20",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.0",
                  "versionStartIncluding": "2.6.20",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/tcp-md5: Fix MAC comparison to be constant-time\n\nTo prevent timing attacks, MACs need to be compared in constant\ntime.  Use the appropriate helper function for this."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 9.4,
            "baseSeverity": "CRITICAL",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:N - The vulnerable comparisons are reached by remotely supplied IPv4/IPv6 TCP packets carrying the TCP MD5 option on TCP-MD5-protected sockets, including Internet-facing BGP deployments.\nAC:L - The attacker can send repeated chosen TCP segments to the verifier and use the non-constant-time comparison as a timing oracle; there is no race or memory-layout dependency beyond the target having TCP MD5 enabled/configured.\nPR:N - The vulnerable receive path is reached before successful TCP MD5 authentication, by unauthenticated network packets; no local account or kernel privilege is required.\nUI:N - No victim user action is required once a TCP-MD5-protected service such as a BGP listener/session is exposed.\nS:U - The impact remains within the same kernel/network security authority enforcing TCP authentication for the protected connection.\nC:L - The timing side channel leaks MAC comparison progress and can enable forgery of authenticated packets, potentially exposing data available through the protected TCP session, but it does not disclose kernel memory or the MD5 key directly.\nI:H - Forging valid TCP MD5 segments can bypass the transport authentication protecting BGP or similar sessions, enabling injection or manipulation of authenticated TCP/application data.\nA:H - Forged authenticated RSTs or disruptive TCP/application traffic can tear down protected routing sessions or otherwise cause significant service disruption."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T12:27:41.847Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/821c8751fdeecdeecabeb11704dd33439c9e4bbc"
        },
        {
          "url": "https://git.kernel.org/stable/c/ff44ec94d4fc8348600a69de0a8fa1102c23bce8"
        },
        {
          "url": "https://git.kernel.org/stable/c/345a9530756528d7ca407663d659c3c40e75c3dd"
        },
        {
          "url": "https://git.kernel.org/stable/c/5d305a95130a8d08b9545e47f1e18d29d59866cb"
        },
        {
          "url": "https://git.kernel.org/stable/c/02669e2a4d207068edce7e8b5fafd85822018ce6"
        },
        {
          "url": "https://git.kernel.org/stable/c/ae3831b44f477de048287493e184fc3ff913b624"
        },
        {
          "url": "https://git.kernel.org/stable/c/b502e97e29d791ff7a8051f29a414535739be218"
        },
        {
          "url": "https://git.kernel.org/stable/c/46d0d6f50dab706637f4c18a470aac20a21900d3"
        }
      ],
      "title": "net/tcp-md5: Fix MAC comparison to be constant-time",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2026-43383",
    "datePublished": "2026-05-08T14:21:30.704Z",
    "dateReserved": "2026-05-01T14:12:56.006Z",
    "dateUpdated": "2026-08-05T12:27:41.847Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…