Improper Initialization in Linux kernel - CVE-2026-45930

 

Improper Initialization in Linux kernel - CVE-2026-45930

Published: May 28, 2026


Vulnerability identifier: #VU132565
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-45930
CWE-ID: CWE-665
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to improper initialization in netlink ndmsg response messages when handling RTM_GETNEIGH requests. A local user can send a crafted netlink request to disclose sensitive information.

The issue affects pad bytes in the ndmsg data returned by the kernel.


Affected software

Linux kernel
Debian Linux
linux (Debian package)

How to mitigate CVE-2026-45930

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3
linux (Debian package) - update to 6.12.94-1

External References

Related Security Bulletins