Back to overview

CVE-2026-46039

CRITICAL
9.8
CVSS 3.1
Description
In the Linux kernel, the following vulnerability has been resolved: rxgk: Fix potential integer overflow in length check Fix potential integer overflow in rxgk_extract_token() when checking the length of the ticket. Rather than rounding up the value to be tested (which might overflow), round down the size of the available data.

Metadata

CVE ID
CVE-2026-46039
State
PUBLISHED
Assigner
Linux
Reserved
2026-05-13 15:03 UTC
Published
2026-05-27 12:56 UTC
Last updated
2026-06-14 17:49 UTC
Vendor / Product
Linux / Linux
Sources
cve.org  ·  NVD

Severity & Metrics

9.8 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products (2)
VendorProductPlatformVersions
Linux Linux 2429a197648178cd4dc930a9d87c13c547460564 < 43222ac484f93b3ec2d240a7575e1cedd31f5fa4, 2429a197648178cd4dc930a9d87c13c547460564 < 183d37f12d1c8ed24a5bfc7addad05510da22a94, 2429a197648178cd4dc930a9d87c13c547460564 < 6929350080f4da292d111a3b33e53138fee51cec, 71571e187106631a8127f2dde780f35caa358d33 …
Linux Linux 6.17, 0 < 6.17, 6.18.27 ≤ 6.18.*, 7.0.4 ≤ 7.0.* …
CVSS scores (1)
ScoreSeverityVersionSourceVector
9.8 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Back to overview