CVE-2026-43456 Explained: 19-Year Linux Kernel Zero-Day Deep Dive (thecybersecguru.com)
from UnLocoPoco@lemmy.world to cybersecurity@infosec.pub on 05 Jul 07:53
https://lemmy.world/post/49049539

CVE-2026-43456 is a local privilege escalation vulnerability in the Linux kernel caused by a flaw in the bonding driver that can lead to use-after-free conditions during interface teardown and state transitions. Under the right conditions, a local attacker can leverage the race to obtain root privileges.

#cybersecurity

threaded - newest

poinck@lemmy.world on 05 Jul 08:55 next collapse

This is already been fixed in Debian stable with linux-6.12.86-1 .

security-tracker.debian.org/…/CVE-2026-43456

UnLocoPoco@lemmy.world on 05 Jul 09:02 collapse

Yup just a PSA to get patched asap

tribut@infosec.pub on 05 Jul 09:15 collapse

Except it does not actually appear on CISA’s KEV list?

cisa.gov/known-exploited-vulnerabilities-catalog