Improper Initialization in Linux kernel - CVE-2026-43040
Published: May 2, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper initialization in ndisc_ra_useropt when processing router advertisements with user options. A remote attacker can send a specially crafted router advertisement to disclose sensitive information.
The issue affects the RTM_NEWNDUSEROPT netlink message because padding fields in the nduseroptmsg structure are not zeroed before being exposed.
How to mitigate CVE-2026-43040
Sources
- https://git.kernel.org/stable/c/11d7fe97421cfc81549940c20ed5ac9472d6db05
- https://git.kernel.org/stable/c/1da9023f6b071a38e5430ffbce4b70b2b1ac4f9c
- https://git.kernel.org/stable/c/2fe4d0ba690a69ad6ae9f7ab9bdc96e02610b648
- https://git.kernel.org/stable/c/4f810c686fde509d1cdaa706322d9d2531f8f1a4
- https://git.kernel.org/stable/c/7f56d87e527bb5a13c3e8b0d5840cb6332822f6d
- https://git.kernel.org/stable/c/ae05340ccaa9d347fe85415609e075545bec589f
- https://git.kernel.org/stable/c/b485eef3d97b7aae55ce669b6de555ec81f3d21c
- https://git.kernel.org/stable/c/ef3645606e4a635d5062a492f22b7f490852ee67