Out-of-bounds read in Linux kernel - CVE-2026-46033
Published: May 28, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to an out-of-bounds access in the authencesn ESN encrypt/decrypt paths when handling AF_ALG requests with a too-short authentication tag inherited from an ahash digest size of 1 to 3 bytes. A local user can select an ahash with a digest size of 1 to 3 bytes and trigger ESN tail handling to cause a denial of service.
How to mitigate CVE-2026-46033
Sources
- https://git.kernel.org/stable/c/5db6ef9847717329f12c5ea8aba7e9f588a980c0
- https://git.kernel.org/stable/c/67f1f0933cc3d78dde222842bcad2778ec7a0b88
- https://git.kernel.org/stable/c/9aff81e8217e9de2929084b03b3c7f81988c112b
- https://git.kernel.org/stable/c/b42821c15445f93daea3e76ada682b2b7181c476
- https://git.kernel.org/stable/c/b69933e97efea238ebbfcf70c2b1be1cd03f13e3