CVE-2026-43383

Source
https://cve.org/CVERecord?id=CVE-2026-43383
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-43383.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-43383
Downstream
Published
2026-05-08T14:21:30.704Z
Modified
2026-05-28T03:54:11.402853739Z
Severity
  • 9.4 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H CVSS Calculator
Summary
net/tcp-md5: Fix MAC comparison to be constant-time
Details

In the Linux kernel, the following vulnerability has been resolved:

net/tcp-md5: Fix MAC comparison to be constant-time

To prevent timing attacks, MACs need to be compared in constant time. Use the appropriate helper function for this.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/43xxx/CVE-2026-43383.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
cfb6eeb4c860592edd123fdea908d23c6ad1c7dc
Fixed
821c8751fdeecdeecabeb11704dd33439c9e4bbc
Fixed
345a9530756528d7ca407663d659c3c40e75c3dd
Fixed
5d305a95130a8d08b9545e47f1e18d29d59866cb
Fixed
02669e2a4d207068edce7e8b5fafd85822018ce6
Fixed
ae3831b44f477de048287493e184fc3ff913b624
Fixed
b502e97e29d791ff7a8051f29a414535739be218
Fixed
46d0d6f50dab706637f4c18a470aac20a21900d3

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-43383.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.6.20
Fixed
5.10.253
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
6.1.167
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.130
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.78
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.19
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
6.19.9

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-43383.json"