PT-2026-44290 · Linux+2 · Linux Kernel+2

CVE-2026-46167

·

Published

2026-04-27

·

Updated

2026-09-07

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 7.0.11-1.1
Description A heap leak exists in the usblp driver. The usblp read status() function requests 1 byte of data, but if a malicious printer responds with zero bytes, the usblp ctrl msg() function discards the actual number of bytes transferred. This results in the statusbuf variable containing one byte of stale kmalloc heap memory, which is then sign-extended into a local integer and passed to the ioctl caller via copy to user() during an LPGETSTATUS ioctl call.
Recommendations Update to version 7.0.11-1.1 or later.

Exploit

Fix

Access of Uninitialized Pointer

Use of Uninitialized Resource

Access of Memory Location After End of Buffer

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-88911
BDU:2026-13839
CVE-2026-46167
ECHO-137F-346E-F581
OESA-2026-2580
OPENSUSE-SU-2026:10954-1
OPENSUSE-SU-2026:21555-1
SUSE-SU-2026:23066-1
SUSE-SU-2026:23068-1
SUSE-SU-2026:23193-1
SUSE-SU-2026:23194-1
SUSE-SU-2026:23221-1
SUSE-SU-2026:23231-1
SUSE-SU-2026:23237-1
SUSE-SU-2026:23241-1
SUSE-SU-2026:23244-1
SUSE-SU-2026:3130-1
SUSE-SU-2026:3166-1
SUSE-SU-2026:3594-1
USN-8566-1
USN-8567-1
USN-8568-1
USN-8569-1
USN-8574-1
USN-8574-2
USN-8574-3
USN-8575-1
USN-8575-2
USN-8575-3
USN-8576-1
USN-8576-2
USN-8593-1
USN-8595-1
USN-8595-2
USN-8595-3
USN-8596-1
USN-8597-1
USN-8603-1
USN-8606-1
USN-8607-1
USN-8608-1
USN-8609-1
USN-8610-1
USN-8618-1
USN-8619-1
USN-8620-1
USN-8620-2
USN-8620-3
USN-8620-4
USN-8663-1
USN-8664-1
USN-8665-1
USN-8668-1
USN-8728-1

Affected Products

Linuxmint
Linux Kernel
Ubuntu