CVE-2026-52975 | Linux Kernel up to 6.1.174/6.6.140/6.18.32/7.0.9 bonding bond_3ad.c __rcu aggregator information disclosure (WID-SEC-2026-2077)
A vulnerability was found in Linux Kernel up to 6.1.174/6.6.140/6.18.32/7.0.9. It has been rated as critical. This affects the function __rcu of the file drivers/net/bonding/bond_3ad.c of the component bonding. The manipulation of the argument aggregator leads to information disclosure.
This vulnerability is documented as CVE-2026-52975. The attack requires being on the local network. There is not any exploit available.
Upgrading the affected component is advised.