PT-2026-43894 · Opensuse+3 · Opensuse Tumbleweed+3
CVE-2026-46027
·
Published
2026-05-27
·
Updated
2026-08-25
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
openSUSE Tumbleweed versions prior to kernel-devel-7.0.11-1.1
Description
An issue exists in the
net/smc module where a CLC decline can be received during the early stages of a handshake, before the connection is associated with a link group. The decline handling in the smc clc wait msg() function attempts to update the link-group level sync state for first-contact declines; however, this state is only available after the link group setup is complete. This leads to premature access to the link-group state.Recommendations
Update to a version of the Linux kernel where the
smc clc wait msg() function is guarded to prevent early link-group access.
Update openSUSE Tumbleweed to kernel-devel-7.0.11-1.1.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linuxmint
Linux Kernel
Ubuntu
Opensuse Tumbleweed