CVE-2026-46026

In the Linux kernel, the following vulnerability has been resolved: net: qrtr: ns: Limit the maximum number of lookups Current code does no bound checking on the number of lookups a client can perform. Though the code restricts the lookups to local clients, there is still a possibility of a malicious local client sending a flood of NEW_LOOKUP messages over the same socket. Fix this issue by limiting the maximum number of lookups to 64 globally. Since the nameserver allows only atmost one local observer, this global lookup count will ensure that the lookups stay within the limit. Note that, limit of 64 is chosen based on the current platform requirements. If requirement changes in the future, this limit can be increased.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

History

19 Jun 2026, 13:16

Type Values Removed Values Added
References
  • () https://git.kernel.org/stable/c/6e3675251fcea06caecc61eb76462467558adfa6 -
  • () https://git.kernel.org/stable/c/91cb30b6bb1880ba0748ca059bef50b8ac13793d -
  • () https://git.kernel.org/stable/c/bd69e0e8a7643ba5385f19f479e8e3da71f8d495 -

16 Jun 2026, 15:54

Type Values Removed Values Added
First Time Linux linux Kernel
Linux
CPE cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
CWE NVD-CWE-noinfo
References () https://git.kernel.org/stable/c/0dbec101a7076e9b1e4bd1876f7cf07c56ff4ce3 - () https://git.kernel.org/stable/c/0dbec101a7076e9b1e4bd1876f7cf07c56ff4ce3 - Patch
References () https://git.kernel.org/stable/c/20855cef7e659ef84ac73251256fa530819b2346 - () https://git.kernel.org/stable/c/20855cef7e659ef84ac73251256fa530819b2346 - Patch
References () https://git.kernel.org/stable/c/2b930bc77e00cb27e1d6e1d497b3b596283465ef - () https://git.kernel.org/stable/c/2b930bc77e00cb27e1d6e1d497b3b596283465ef - Patch
References () https://git.kernel.org/stable/c/5640227d9a21c6a8be249a10677b832e7f40dc55 - () https://git.kernel.org/stable/c/5640227d9a21c6a8be249a10677b832e7f40dc55 - Patch
References () https://git.kernel.org/stable/c/76adf8f69b0bb3ab20be7c58f5d555027332d113 - () https://git.kernel.org/stable/c/76adf8f69b0bb3ab20be7c58f5d555027332d113 - Patch

27 May 2026, 14:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-27 14:17

Updated : 2026-06-19 13:16


NVD link : CVE-2026-46026

Mitre link : CVE-2026-46026

CVE.ORG link : CVE-2026-46026


JSON object : View

Products Affected

linux

  • linux_kernel