ZDI-26-701: Linux Kernel TLS Protocol Out-Of-Bounds Read Information Disclosure Vulnerability
This vulnerability allows local attackers to disclose sensitive information on affected installations of Linux Kernel. An attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.7. The following CVEs are assigned: CVE-2026-64046.
Affected Software
Event History
Frequently Asked Questions
Who is realistically exposed to this issue?
Affected Linux Kernel installations are exposed only to attackers who can execute high-privileged code locally on the target system. It is therefore most relevant where privileged local code execution has already been obtained or delegated.
What does an attacker need to exploit the vulnerability?
The attacker must first gain the ability to execute high-privileged code on the target system. The provided information does not describe a remote exploitation path or any additional prerequisites.