CVE-2026-43456 Explained: 19-Year Linux Kernel Zero-Day Deep Dive
(thecybersecguru.com)
from UnLocoPoco@lemmy.world to cybersecurity@infosec.pub on 05 Jul 07:53
https://lemmy.world/post/49049539
from UnLocoPoco@lemmy.world to cybersecurity@infosec.pub on 05 Jul 07:53
https://lemmy.world/post/49049539
CVE-2026-43456 is a local privilege escalation vulnerability in the Linux kernel caused by a flaw in the bonding driver that can lead to use-after-free conditions during interface teardown and state transitions. Under the right conditions, a local attacker can leverage the race to obtain root privileges.
threaded - newest
This is already been fixed in Debian stable with linux-6.12.86-1 .
security-tracker.debian.org/…/CVE-2026-43456
Yup just a PSA to get patched asap
Except it does not actually appear on CISA’s KEV list?
cisa.gov/known-exploited-vulnerabilities-catalog