PT-2026-37399 · Linux+2 · Linux Kernel+2
CVE-2026-43089
·
Published
2026-04-06
·
Updated
2026-08-25
CVSS v2.0
6.0
Medium
| Vector | AV:L/AC:H/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
An information leak exists in the
build mapping() function within the xfrm user component. The xfrm usersa id structure contains a one-byte padding hole following the proto field that is not zeroed before being copied to userspace, potentially exposing sensitive data.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Use of Uninitialized Resource
Memory Leak
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linuxmint
Linux Kernel
Ubuntu