Use of Uninitialized Variable in Linux kernel - CVE-2026-43026
Published: May 2, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to use of uninitialized memory in ctnetlink expectation handling when processing a netlink message without CTA_EXPECT_NAT. A remote user can send a specially crafted netlink message to disclose sensitive information.
The issue can cause stale data from a previous slab allocation to be exposed in a dumped CTA_EXPECT_NAT attribute, and it is relevant only when NAT support is enabled.
How to mitigate CVE-2026-43026
Sources
- https://git.kernel.org/stable/c/1c2ebdeff8d088a2e47ae25d7b38447249adace2
- https://git.kernel.org/stable/c/2898080c054ea4d6ddfaaf21bbedbc229a9a8376
- https://git.kernel.org/stable/c/35177c6877134a21315f37d57a5577846225623e
- https://git.kernel.org/stable/c/929f7a9a7aad9404a5867216c3f8738232355b38
- https://git.kernel.org/stable/c/a5a89db6981a1ddf2314bf50cb49db5a3146185f
- https://git.kernel.org/stable/c/a64b7bf84b4d5ea54218c5d374ec87fff9000f43
- https://git.kernel.org/stable/c/bff0f4f06f12d6d9bc565a3e1378abd4f6f5ce36
- https://git.kernel.org/stable/c/fd002ff2ea030cbfb0188a11b3c60ce7f84485f4