PT-2026-43879 · Opensuse+3 · Opensuse Tumbleweed+3

CVE-2026-46012

·

Published

2026-05-27

·

Updated

2026-08-25

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified) openSUSE Tumbleweed versions prior to kernel-devel-7.0.11-1.1
Description A memory leak occurs in the rxkad verify response() function within the rxrpc component. The issue arises when the ticket and server key are not properly freed under all execution paths.
Recommendations Update to a version where the rxkad verify response() function is patched to ensure the ticket pointer is initialized to NULL and all paths lead to a common epilogue for resource release. Update openSUSE Tumbleweed to version kernel-devel-7.0.11-1.1.

Exploit

Fix

Memory Leak

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-88677
CVE-2026-46012
ECHO-2BCA-5E0C-F6C8
OPENSUSE-SU-2026:10954-1
USN-8488-1
USN-8488-2
USN-8489-1
USN-8507-1
USN-8567-1
USN-8569-1
USN-8574-1
USN-8574-2
USN-8574-3
USN-8595-1
USN-8595-2
USN-8595-3
USN-8596-1
USN-8603-1
USN-8606-1
USN-8607-1
USN-8608-1
USN-8609-1
USN-8619-1
USN-8665-1

Affected Products

Linuxmint
Linux Kernel
Ubuntu
Opensuse Tumbleweed