【活用ガイド】

JVNDB-2026-014976

LinuxのLinux Kernelにおけるリソースの初期化の不備に関する脆弱性

概要

Linuxカーネルにおいて、以下の脆弱性が修正されました。net: ipv6: ndisc: ndisc_ra_useropt関数でnduseropt_padXフィールドをゼロ初期化して情報漏洩を防止します。ルーター広告のユーザーオプションを処理する際に、カーネルはRTM_NEWNDUSEROPTのnetlinkメッセージを構築します。nduseroptmsg構造体には3つのパディングフィールドがあり、これらはゼロ初期化されなかったため、カーネルデータが漏洩する可能性がありました。修正は簡単で、パディングフィールドをゼロクリアする処置を行います。
CVSS による深刻度 (CVSS とは?)

CVSS v3 による深刻度
基本値: 7.1 (重要) [NVD値]
  • 攻撃元区分: ローカル
  • 攻撃条件の複雑さ: 低
  • 攻撃に必要な特権レベル: 低
  • 利用者の関与: 不要
  • 影響の想定範囲: 変更なし
  • 機密性への影響(C): 高
  • 完全性への影響(I): なし
  • 可用性への影響(A): 高
影響を受けるシステム


Linux
  • Linux Kernel 2.6.24 以上 5.10.253 未満
  • Linux Kernel 5.11 以上 5.15.203 未満
  • Linux Kernel 5.16 以上 6.1.168 未満
  • Linux Kernel 6.13 以上 6.18.22 未満
  • Linux Kernel 6.19 以上 6.19.12 未満
  • Linux Kernel 6.2 以上 6.6.134 未満
  • Linux Kernel 6.7 以上 6.12.81 未満
  • Linux Kernel 7.0

想定される影響

当該ソフトウェアが扱う全ての情報が外部に漏れる可能性があります。
また、当該ソフトウェアが扱う情報について、書き換えは発生しません。
さらに、当該ソフトウェアが完全に停止する可能性があります。
そして、この脆弱性を悪用した攻撃の影響は、他のソフトウェアには及びません。
対策

リリース情報、またはパッチ情報が公開されています。参考情報を参照して適切な対策を実施してください。
ベンダ情報

CWEによる脆弱性タイプ一覧  CWEとは?

  1. リソースの初期化の不備(CWE-909) [NVD評価]
共通脆弱性識別子(CVE)  CVEとは?

  1. CVE-2026-43040
参考情報

  1. National Vulnerability Database (NVD) : CVE-2026-43040
  2. 関連文書 : net: ipv6: ndisc: fix ndisc_ra_useropt to initialize nduseropt_padX fields to zero to prevent an info-leak - kernel/git/stable/linux.git - Linux kernel stable tree (https://git.kernel.org/stable/c/ef3645606e4a635d5062a492f22b7f490852ee67)
  3. 関連文書 : net: ipv6: ndisc: fix ndisc_ra_useropt to initialize nduseropt_padX fields to zero to prevent an info-leak - kernel/git/stable/linux.git - Linux kernel stable tree (https://git.kernel.org/stable/c/1da9023f6b071a38e5430ffbce4b70b2b1ac4f9c)
  4. 関連文書 : net: ipv6: ndisc: fix ndisc_ra_useropt to initialize nduseropt_padX fields to zero to prevent an info-leak - kernel/git/stable/linux.git - Linux kernel stable tree (https://git.kernel.org/stable/c/7f56d87e527bb5a13c3e8b0d5840cb6332822f6d)
  5. 関連文書 : net: ipv6: ndisc: fix ndisc_ra_useropt to initialize nduseropt_padX fields to zero to prevent an info-leak - kernel/git/stable/linux.git - Linux kernel stable tree (https://git.kernel.org/stable/c/2fe4d0ba690a69ad6ae9f7ab9bdc96e02610b648)
  6. 関連文書 : net: ipv6: ndisc: fix ndisc_ra_useropt to initialize nduseropt_padX fields to zero to prevent an info-leak - kernel/git/stable/linux.git - Linux kernel stable tree (https://git.kernel.org/stable/c/4f810c686fde509d1cdaa706322d9d2531f8f1a4)
  7. 関連文書 : net: ipv6: ndisc: fix ndisc_ra_useropt to initialize nduseropt_padX fields to zero to prevent an info-leak - kernel/git/stable/linux.git - Linux kernel stable tree (https://git.kernel.org/stable/c/11d7fe97421cfc81549940c20ed5ac9472d6db05)
  8. 関連文書 : net: ipv6: ndisc: fix ndisc_ra_useropt to initialize nduseropt_padX fields to zero to prevent an info-leak - kernel/git/stable/linux.git - Linux kernel stable tree (https://git.kernel.org/stable/c/ae05340ccaa9d347fe85415609e075545bec589f)
  9. 関連文書 : net: ipv6: ndisc: fix ndisc_ra_useropt to initialize nduseropt_padX fields to zero to prevent an info-leak - kernel/git/stable/linux.git - Linux kernel stable tree (https://git.kernel.org/stable/c/b485eef3d97b7aae55ce669b6de555ec81f3d21c)
更新履歴

  • [2026年05月11日]
      掲載