ZDI-CAN-28594: ZDI-26-682: Linux Kernel IPv6 Neighbour Discovery Uninitialized Memory Information Disclosure Vulnerability
This vulnerability allows local attackers to disclose sensitive information on affected installations of Linux Kernel. An attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.0. The following CVEs are assigned: CVE-2026-43040.
Affected Software
Event History
Frequently Asked Questions
Who is realistically exposed to exploitation?
Exploitation requires local execution of high-privileged code on the affected system. This limits exposure to attackers who have already obtained significant privileges or to trusted high-privilege local processes.
What access does an attacker need to exploit the issue?
The attacker must be able to execute high-privileged code on the target Linux system. The provided information does not indicate that unprivileged local users or remote attackers can exploit it.
What is the impact if exploitation succeeds?
A successful exploit can disclose sensitive information from uninitialized memory through Linux Kernel IPv6 Neighbour Discovery functionality. The assigned CVSS rating is 6.0.