PT-2026-43905 · Opensuse+1 · Opensuse Tumbleweed+1

CVE-2026-46038

·

Published

2026-05-27

·

Updated

2026-07-28

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified) openSUSE Tumbleweed versions prior to kernel-devel-7.0.11-1.1
Description A memory leak occurs in the QualComm Rapid Transport (QRTR) nameserver. When a node sends a BYE packet indicating it is going down, the nameserver fails to free the node memory after processing the packet. This issue is addressed by ensuring the node is removed from the Xarray list and its memory is freed during both success and failure cases of the ctrl cmd bye() function.
Recommendations Update to a version of the Linux kernel where the ctrl cmd bye() function correctly frees node memory. Update to kernel-devel-7.0.11-1.1 or a newer version.

Exploit

Fix

Memory Leak

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-46038
ECHO-8135-82A8-8796
OPENSUSE-SU-2026:10954-1
USN-8488-1
USN-8488-2
USN-8489-1
USN-8507-1
USN-8567-1
USN-8569-1
USN-8574-1
USN-8574-2
USN-8574-3
USN-8595-1
USN-8595-2
USN-8595-3
USN-8596-1
USN-8603-1
USN-8606-1
USN-8607-1
USN-8608-1
USN-8609-1
USN-8619-1

Affected Products

Linux Kernel
Opensuse Tumbleweed