cbcvebase.
CVE-2026-43383
published 2026-05-08

CVE-2026-43383: In the Linux kernel, the following vulnerability has been resolved: net/tcp-md5: Fix MAC comparison to be constant-time To prevent timing attacks, MACs need to…

PriorityP345critical9.4CVSS 3.1
AVNACLPRNUINSUCLIHAH
EPSS
0.44%
35.9th percentile
In the Linux kernel, the following vulnerability has been resolved: net/tcp-md5: Fix MAC comparison to be constant-time To prevent timing attacks, MACs need to be compared in constant time. Use the appropriate helper function for this.

Affected

66 ranges· showing 25
VendorProductVersion rangeFixed in
linuxlinux
linuxlinux>= cfb6eeb4c860592edd123fdea908d23c6ad1c7dc < 821c8751fdeecdeecabeb11704dd33439c9e4bbc821c8751fdeecdeecabeb11704dd33439c9e4bbc
linuxlinux>= cfb6eeb4c860592edd123fdea908d23c6ad1c7dc < ff44ec94d4fc8348600a69de0a8fa1102c23bce8ff44ec94d4fc8348600a69de0a8fa1102c23bce8
linuxlinux>= cfb6eeb4c860592edd123fdea908d23c6ad1c7dc < 345a9530756528d7ca407663d659c3c40e75c3dd345a9530756528d7ca407663d659c3c40e75c3dd
linuxlinux>= cfb6eeb4c860592edd123fdea908d23c6ad1c7dc < 5d305a95130a8d08b9545e47f1e18d29d59866cb5d305a95130a8d08b9545e47f1e18d29d59866cb
linuxlinux>= cfb6eeb4c860592edd123fdea908d23c6ad1c7dc < 02669e2a4d207068edce7e8b5fafd85822018ce602669e2a4d207068edce7e8b5fafd85822018ce6
linuxlinux>= cfb6eeb4c860592edd123fdea908d23c6ad1c7dc < ae3831b44f477de048287493e184fc3ff913b624ae3831b44f477de048287493e184fc3ff913b624
linuxlinux>= cfb6eeb4c860592edd123fdea908d23c6ad1c7dc < b502e97e29d791ff7a8051f29a414535739be218b502e97e29d791ff7a8051f29a414535739be218
linuxlinux>= cfb6eeb4c860592edd123fdea908d23c6ad1c7dc < 46d0d6f50dab706637f4c18a470aac20a21900d346d0d6f50dab706637f4c18a470aac20a21900d3
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 2.6.20 < 5.10.2535.10.253
linuxlinux_kernel>= 5.11 < 6.1.1676.1.167
linuxlinux_kernel>= 6.13 < 6.18.196.18.19
linuxlinux_kernel>= 6.19 < 6.19.96.19.9
linuxlinux_kernel>= 6.2 < 6.6.1306.6.130
linuxlinux_kernel>= 6.7 < 6.12.786.12.78
ubuntulinux
ubuntulinux-aws
ubuntulinux-aws-5.15
ubuntulinux-aws-6.8
ubuntulinux-aws-fips
ubuntulinux-azure
ubuntulinux-azure-4.15

CVSS provenance

nvdv3.19.4CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H
vendor_ubuntu8.8HIGH
vendor_redhat7.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.