CVE-2026-43384

Description

A flaw was found in the Linux kernel's TCP Authentication Option (TCP-AO) implementation. This vulnerability arises from a non-constant-time comparison of Message Authentication Codes (MACs). A remote attacker could potentially exploit this timing discrepancy to perform a timing attack, which may lead to the disclosure of sensitive information.

Understanding the Weakness (CWE)

Confidentiality,Access Control

Technical Impact: Read Application Data; Bypass Protection Mechanism

Frequently Asked Questions

Want to get errata notifications? Sign up here.