CVE-2026-43384

Updated on 08 May 2026

Severity

9.8 Critical severity

Details

CVSS score
9.8

Overview

About vulnerability

In the Linux kernel, the following vulnerability has been resolved: net/tcp-ao: Fix MAC comparison to be constant-time To prevent timing attacks, MACs need to be compared in constant time. Use the appropriate helper function for this. A flaw was found in the Linux kernel’s TCP Authentication Option (TCP-AO) implementation. This vulnerability arises from a non-constant-time comparison of Message Authentication Codes (MACs). A remote attacker could potentially exploit this timing discrepancy to perform a timing attack, which may lead to the disclosure of sensitive information.

Details

KernelCare state

Live-patch status from KernelCare for each operating system.

Operating system Status Covered kernels
Debian 13 Planned
Ubuntu 24.04 Planned
Ubuntu 24.04 AWS Planned