Use of Uninitialized Variable in Linux kernel - CVE-2026-43139
Published: May 7, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to use of uninitialized memory in xfrm6_get_saddr() when handling IPv6 source address selection failures. A local user can trigger network operations that cause ipv6_dev_get_saddr() to fail and use the uninitialized address to cause a denial of service.
How to mitigate CVE-2026-43139
Sources
- https://git.kernel.org/stable/c/1799d8abeabc68ec05679292aaf6cba93b343c05
- https://git.kernel.org/stable/c/3dcd1664ac15eee6a690daec7c4ffc59190406f7
- https://git.kernel.org/stable/c/4f28141786e1fe884ce42a5197ba9beed540f0ea
- https://git.kernel.org/stable/c/6535867673bf301d52aa00593a4d1d18cc3922fa
- https://git.kernel.org/stable/c/719918fc88df6da023dfff370cd965151a5afd7f
- https://git.kernel.org/stable/c/c7221e7bd8fc2ef38a0b27be580d9d202281306b
- https://git.kernel.org/stable/c/dc0abce055134cb83b0d981d31ceb20dda419787
- https://git.kernel.org/stable/c/eb2ee15290af14c60b45cf2b73f5687d1d077d9b