ZDI-CAN-30511: ZDI-26-701: Linux Kernel TLS Protocol Out-Of-Bounds Read Information Disclosure Vulnerability
This vulnerability allows local attackers to disclose sensitive information on affected installations of Linux Kernel. An attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.7. The following CVEs are assigned: CVE-2026-64046.
Affected Software
Event History
Frequently Asked Questions
Who is realistically exposed to this issue?
Systems running an affected Linux Kernel installation are exposed only after an attacker has obtained the ability to execute high-privileged code locally on the target.
What access does an attacker need to exploit it?
The attacker needs high-privileged code execution on the target system. The provided information does not describe a remote or unprivileged exploitation path.
What is the potential impact after exploitation?
Successful exploitation can disclose sensitive information through an out-of-bounds read in the Linux Kernel TLS protocol handling.