Back

CRITICAL

net/tcp-md5: Fix MAC comparison to be constant-time

Published May 8, 2026

Description

To prevent timing attacks, MACs need to be compared in constant time. Use the appropriate helper function for this.

Affected products

Remediation

Red Hat statement

Red Hat acknowledges the upstream Linux kernel correction for «net/tcp-md5» as described in COMMENT_ZERO. Fixes are delivered through standard kernel errata for supported products. Operational exposure depends on whether this subsystem or driver is active in your configuration.

Weaknesses (1)

References (14)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Linux
Published May 8, 2026
Updated Aug 5, 2026
Reserved May 1, 2026
NVD
Status Modified
Modified Jun 19, 2026
Red Hat
Severity Moderate
Public date May 8, 2026
ENISA EUVD
Assigner Linux
Published May 8, 2026
Updated Aug 5, 2026
Exploited since n/a
EUVD-2026-28689