SB2026052848 - Improper Initialization in Linux kernel smc
Published: May 28, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper Initialization (CVE-ID: CVE-2026-46027)
CWE-ID: CWE-665 - Improper Initialization
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper access to uninitialized state in smc_clc_wait_msg() when handling a CLC decline during an early handshake stage before link group association. A remote attacker can send a specially crafted decline message to cause a denial of service.
The issue occurs for first-contact declines received before link group setup has completed.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/5a8db80f721deee8e916c2cfdee78decda02ce4f
- https://git.kernel.org/stable/c/6180a296ca65b08a81914805cbc0f78da5f10a1f
- https://git.kernel.org/stable/c/83bcf9228b0501694fb2589ed1d142855a2887f2
- https://git.kernel.org/stable/c/ea0b5d0fe96356dce38f98375a57c52a04e13712
- https://git.kernel.org/stable/c/f0858e1d5624bb120b198f2a8528f97a9b0ae069