PT-2026-43904 · Linux+3 · Linux Kernel+3

CVE-2026-46037

·

Published

2026-05-27

·

Updated

2026-08-31

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified) openSUSE Tumbleweed versions prior to kernel-devel-7.0.11-1.1
Description A flaw exists in the IPv4 ICMP implementation where the system fails to validate the reply type before accessing the icmp pointers[] array. Extended echo replies utilize ICMP EXT ECHOREPLY as the outbound reply type, which falls outside the range covered by icmp pointers[] (which only describes traditional ICMP types up to NR ICMP TYPES). This can lead to an out-of-bounds access when consulting the array for reply types outside the supported range.
Recommendations Update to kernel-devel-7.0.11-1.1 for openSUSE Tumbleweed. At the moment, there is no information about a newer version that contains a fix for this vulnerability for the Linux kernel.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-88671
CVE-2026-46037
ECHO-CA81-9856-7C07
OPENSUSE-SU-2026:10954-1
OPENSUSE-SU-2026:21388-1
SUSE-SU-2026:22433-1
SUSE-SU-2026:22436-1
SUSE-SU-2026:22458-1
SUSE-SU-2026:22460-1
SUSE-SU-2026:22742-1
SUSE-SU-2026:22769-1
SUSE-SU-2026:22812-1
SUSE-SU-2026:22835-1
SUSE-SU-2026:23258-1
SUSE-SU-2026:23259-1
SUSE-SU-2026:23260-1
SUSE-SU-2026:23261-1
SUSE-SU-2026:23262-1
SUSE-SU-2026:23263-1
SUSE-SU-2026:23264-1
SUSE-SU-2026:23265-1
SUSE-SU-2026:23266-1
SUSE-SU-2026:23267-1
SUSE-SU-2026:23268-1
SUSE-SU-2026:23269-1
SUSE-SU-2026:23270-1
SUSE-SU-2026:23271-1
SUSE-SU-2026:23272-1
SUSE-SU-2026:23280-1
SUSE-SU-2026:23281-1
SUSE-SU-2026:23282-1
SUSE-SU-2026:23283-1
SUSE-SU-2026:23284-1
SUSE-SU-2026:23285-1
SUSE-SU-2026:23286-1
SUSE-SU-2026:23287-1
SUSE-SU-2026:23288-1
SUSE-SU-2026:23290-1
SUSE-SU-2026:23291-1
SUSE-SU-2026:23292-1
SUSE-SU-2026:23293-1
SUSE-SU-2026:23295-1
SUSE-SU-2026:23296-1
SUSE-SU-2026:23329-1
SUSE-SU-2026:23330-1
SUSE-SU-2026:23331-1
SUSE-SU-2026:23332-1
SUSE-SU-2026:23333-1
SUSE-SU-2026:23334-1
SUSE-SU-2026:23335-1
SUSE-SU-2026:23336-1
SUSE-SU-2026:23337-1
SUSE-SU-2026:23338-1
SUSE-SU-2026:23339-1
SUSE-SU-2026:23340-1
SUSE-SU-2026:23341-1
SUSE-SU-2026:23342-1
SUSE-SU-2026:23343-1
SUSE-SU-2026:23366-1
SUSE-SU-2026:23367-1
SUSE-SU-2026:23368-1
SUSE-SU-2026:23369-1
SUSE-SU-2026:23370-1
SUSE-SU-2026:23371-1
SUSE-SU-2026:23372-1
SUSE-SU-2026:23373-1
SUSE-SU-2026:23374-1
SUSE-SU-2026:23375-1
SUSE-SU-2026:23376-1
SUSE-SU-2026:23377-1
SUSE-SU-2026:23378-1
SUSE-SU-2026:23379-1
SUSE-SU-2026:23383-1
SUSE-SU-2026:23384-1
SUSE-SU-2026:23385-1
SUSE-SU-2026:23386-1
SUSE-SU-2026:23387-1
SUSE-SU-2026:23388-1
SUSE-SU-2026:23389-1
SUSE-SU-2026:23390-1
SUSE-SU-2026:2630-1
SUSE-SU-2026:2631-1
SUSE-SU-2026:2632-1
SUSE-SU-2026:2638-1
SUSE-SU-2026:2658-1
SUSE-SU-2026:2722-1
SUSE-SU-2026:2799-1
SUSE-SU-2026:3689-1
SUSE-SU-2026:3694-1
SUSE-SU-2026:3696-1
SUSE-SU-2026:3697-1
SUSE-SU-2026:3698-1
SUSE-SU-2026:3699-1
SUSE-SU-2026:3700-1
SUSE-SU-2026:3702-1
SUSE-SU-2026:3703-1
SUSE-SU-2026:3704-1
SUSE-SU-2026:3707-1
SUSE-SU-2026:3708-1
SUSE-SU-2026:3709-1
SUSE-SU-2026:3710-1
SUSE-SU-2026:3715-1
SUSE-SU-2026:3719-1
SUSE-SU-2026:3721-1
SUSE-SU-2026:3722-1
SUSE-SU-2026:3724-1
SUSE-SU-2026:3726-1
SUSE-SU-2026:3728-1
SUSE-SU-2026:3729-1
SUSE-SU-2026:3739-1
SUSE-SU-2026:3744-1
SUSE-SU-2026:3746-1
SUSE-SU-2026:3747-1
SUSE-SU-2026:3748-1
SUSE-SU-2026:3750-1
SUSE-SU-2026:3754-1
SUSE-SU-2026:3756-1
SUSE-SU-2026:3757-1
SUSE-SU-2026:3759-1
SUSE-SU-2026:3760-1
SUSE-SU-2026:3761-1
SUSE-SU-2026:3766-1
SUSE-SU-2026:3768-1
SUSE-SU-2026:3770-1
SUSE-SU-2026:3771-1
SUSE-SU-2026:3774-1
SUSE-SU-2026:3775-1
SUSE-SU-2026:3776-1
SUSE-SU-2026:3778-1
SUSE-SU-2026:3779-1
USN-8488-1
USN-8488-2
USN-8489-1
USN-8507-1
USN-8567-1
USN-8569-1
USN-8574-1
USN-8574-2
USN-8574-3
USN-8575-1
USN-8575-2
USN-8575-3
USN-8576-1
USN-8576-2
USN-8595-1
USN-8595-2
USN-8595-3
USN-8596-1
USN-8597-1
USN-8603-1
USN-8606-1
USN-8607-1
USN-8608-1
USN-8609-1
USN-8610-1
USN-8619-1
USN-8620-1
USN-8620-2
USN-8620-3
USN-8620-4
USN-8665-1
USN-8668-1

Affected Products

Linuxmint
Linux Kernel
Ubuntu
Opensuse Tumbleweed