ZDI-26-682: Linux Kernel IPv6 Neighbour Discovery Uninitialized Memory Information Disclosure Vulnerability
This vulnerability allows local attackers to disclose sensitive information on affected installations of Linux Kernel. An attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.0. The following CVEs are assigned: CVE-2026-43040.
Affected Software
Event History
Frequently Asked Questions
Who is realistically exposed to this issue?
Affected Linux Kernel installations are exposed only to attackers who can execute high-privileged code locally on the target system. The provided information does not indicate remote exploitation.
What does an attacker need before exploiting the vulnerability?
The attacker must first obtain the ability to execute high-privileged code on the target system. The issue is therefore relevant as a post-compromise information-disclosure opportunity rather than an initial-access vulnerability.
What is the impact if exploitation succeeds?
Successful exploitation allows disclosure of sensitive information from uninitialized memory. ZDI assigned the issue a CVSS rating of 6.0.