PT-2026-44239 · Linux+1 · Linux Kernel+1

CVE-2026-46116

·

Published

2026-05-28

·

Updated

2026-07-28

CVSS v3.1

7.0

High

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.12.47
Description A slab-use-after-free and out-of-bounds write issue exists in the Linux kernel's xfrm module. The problem occurs within the xfrm state delete() function, where unhashing of byseq and byspi lists relied on value-based predicates instead of checking the actual list state. This inconsistency allows paths to skip or hit the unhash process incorrectly. Additionally, the bydst and bysrc unhashes lacked predicates entirely, leading to writes through LIST POISON during secondary deletions. The issue manifests during the xfrm state lifecycle, specifically affecting functions such as xfrm state lookup(), xfrm alloc spi(), and xfrm state insert() on the byseq/byspi hash chains.
Recommendations Update the Linux kernel to version 6.12.47 or later. As a temporary mitigation, restrict the use of IPsec and xfrm state configurations to minimize the risk of triggering the xfrm state delete() function.

Exploit

Fix

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:36018
ALSA-2026:39179
ALSA-2026:39180
ALSA-2026:42919
CVE-2026-46116
ECHO-C00C-E4EC-3A9B
OESA-2026-2674
OPENSUSE-SU-2026:10954-1
OPENSUSE-SU-2026:21388-1
RHSA-2026:39371
RHSA-2026:41234
RHSA-2026:41235
SUSE-SU-2026:22521-1
SUSE-SU-2026:22522-1
SUSE-SU-2026:22665-1
SUSE-SU-2026:22666-1
SUSE-SU-2026:22742-1
SUSE-SU-2026:22769-1
SUSE-SU-2026:22812-1
SUSE-SU-2026:22835-1
SUSE-SU-2026:2450-1
SUSE-SU-2026:2630-1
SUSE-SU-2026:2631-1
SUSE-SU-2026:2638-1
SUSE-SU-2026:2658-1
SUSE-SU-2026:2799-1
SUSE-SU-2026:2800-1
SUSE-SU-2026:3156-1
USN-8566-1
USN-8567-1
USN-8568-1
USN-8569-1
USN-8574-1
USN-8574-2
USN-8574-3
USN-8593-1
USN-8595-1
USN-8595-2
USN-8595-3
USN-8596-1
USN-8603-1
USN-8606-1
USN-8607-1
USN-8608-1
USN-8609-1
USN-8618-1
USN-8619-1

Affected Products

Linux Kernel
Rocky Linux