Improper Initialization in Linux kernel - CVE-2026-45930
Published: May 28, 2026
Vulnerability details
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to improper initialization in netlink ndmsg response messages when handling RTM_GETNEIGH requests. A local user can send a crafted netlink request to disclose sensitive information.
The issue affects pad bytes in the ndmsg data returned by the kernel.
Affected software
Debian Linux
linux (Debian package)
How to mitigate CVE-2026-45930
linux (Debian package) - update to 6.12.94-1