Affects Linux kernel (core infrastructure) used widely; timing-attack risk in TCP MD5 verification.
CVE-2026-43383
Linux kernel TCP-MD5 MAC check fixed to be constant-time.
Is CVE-2026-43383 being exploited?
Not confirmed. CVE-2026-43383 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.44% probability of exploitation in the next 30 days.
How severe is CVE-2026-43383?
CVE-2026-43383 is rated Critical with a CVSS score of 9.4. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-43383?
Yes. A fix has been recorded for CVE-2026-43383. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-43383 affect?
CVE-2026-43383 affects Linux kernel (net/tcp-md5). Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-43383?
Apply kernel update containing the constant-time MAC fix.
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Timing-side channel in TCP-MD5 MAC verification could leak MAC data.
Patch when possible
- affected>= cfb6eeb4c860592edd123fdea908d23c6ad1c7dc and < 821c8751fdeecdeecabeb11704dd33439c9e4bbc
- affected>= cfb6eeb4c860592edd123fdea908d23c6ad1c7dc and < ff44ec94d4fc8348600a69de0a8fa1102c23bce8
- affected>= cfb6eeb4c860592edd123fdea908d23c6ad1c7dc and < 345a9530756528d7ca407663d659c3c40e75c3dd
- affected>= cfb6eeb4c860592edd123fdea908d23c6ad1c7dc and < 5d305a95130a8d08b9545e47f1e18d29d59866cb
- affected>= cfb6eeb4c860592edd123fdea908d23c6ad1c7dc and < 02669e2a4d207068edce7e8b5fafd85822018ce6
- affected>= cfb6eeb4c860592edd123fdea908d23c6ad1c7dc and < ae3831b44f477de048287493e184fc3ff913b624
- affected>= cfb6eeb4c860592edd123fdea908d23c6ad1c7dc and < b502e97e29d791ff7a8051f29a414535739be218
- affected>= cfb6eeb4c860592edd123fdea908d23c6ad1c7dc and < 46d0d6f50dab706637f4c18a470aac20a21900d3
- affected2.6.20
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.