CVE-2026-46039
CRITICAL
9.8
CVSS 3.1
Description
In the Linux kernel, the following vulnerability has been resolved:
rxgk: Fix potential integer overflow in length check
Fix potential integer overflow in rxgk_extract_token() when checking the
length of the ticket. Rather than rounding up the value to be tested
(which might overflow), round down the size of the available data.
Metadata
Severity & Metrics
9.8
CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products (2)
| Vendor | Product | Platform | Versions |
|---|---|---|---|
| Linux | Linux | — | 2429a197648178cd4dc930a9d87c13c547460564 < 43222ac484f93b3ec2d240a7575e1cedd31f5fa4, 2429a197648178cd4dc930a9d87c13c547460564 < 183d37f12d1c8ed24a5bfc7addad05510da22a94, 2429a197648178cd4dc930a9d87c13c547460564 < 6929350080f4da292d111a3b33e53138fee51cec, 71571e187106631a8127f2dde780f35caa358d33 … |
| Linux | Linux | — | 6.17, 0 < 6.17, 6.18.27 ≤ 6.18.*, 7.0.4 ≤ 7.0.* … |
CVSS scores (1)
| Score | Severity | Version | Source | Vector |
|---|---|---|---|---|
| 9.8 | CRITICAL | 3.1 | cna | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
References (3)