PT-2026-43952 · Opensuse+1 · Opensuse Tumbleweed+1

Published

2026-05-27

·

Updated

2026-06-04

·

CVE-2026-46085

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified) openSUSE Tumbleweed versions prior to kernel-devel-7.0.11-1.1
Description An issue exists in the rxrpc component regarding the handling of packets with misaligned crypto lengths. The system fails to properly manage non-ENOMEM errors during decryption, which should instead result in an abort. Additionally, a WARN ON ONCE() function was present that could be triggered remotely.
Recommendations Update to a version where the rxrpc crypto unalignment handling is fixed. Update to kernel-devel-7.0.11-1.1 or a newer version.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-46085
OPENSUSE-SU-2026:10954-1

Affected Products

Linux Kernel
Opensuse Tumbleweed