PT-2026-36452 · Linux · Linux Kernel

Published

2026-03-29

·

Updated

2026-05-02

·

CVE-2026-43035

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An information leak occurs in the Linux kernel when building netlink messages. The tc chain fill node() function fails to initialize the tcm info field of the struct tcmsg structure. Because the allocation is not zeroed, 4 bytes of kernel heap memory are leaked to userspace.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Use of Uninitialized Resource

Weakness Enumeration

Related Identifiers

BDU:2026-06493
CVE-2026-43035
ECHO-F3AF-26DA-7EE5

Affected Products

Linux Kernel