CVE-2026-43456 is a local privilege escalation vulnerability in the Linux kernel caused by a flaw in the bonding driver that can lead to use-after-free conditions during interface teardown and state transitions. Under the right conditions, a local attacker can leverage the race to obtain root privileges.
CVE-2026-43456 Explained: 19-Year Linux Kernel Zero-Day Deep Dive
https://thecybersecguru.com/exploits/cve-2026-43456-linux-kernel-zero-day/
2 Comments
poinck@lemmy.world · 7 pts · 40d
UnLocoPoco@lemmy.world · 5 pts · 40d
Yup just a PSA to get patched asap
tribut@infosec.pub · 1 pts · 40d
Except it does not actually appear on CISA's KEV list?
https://www.cisa.gov/known-exploited-vulnerabilities-catalog