Improper Initialization in Linux kernel - CVE-2026-46027
Published: May 28, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper access to uninitialized state in smc_clc_wait_msg() when handling a CLC decline during an early handshake stage before link group association. A remote attacker can send a specially crafted decline message to cause a denial of service.
The issue occurs for first-contact declines received before link group setup has completed.
How to mitigate CVE-2026-46027
Sources
- https://git.kernel.org/stable/c/5a8db80f721deee8e916c2cfdee78decda02ce4f
- https://git.kernel.org/stable/c/6180a296ca65b08a81914805cbc0f78da5f10a1f
- https://git.kernel.org/stable/c/83bcf9228b0501694fb2589ed1d142855a2887f2
- https://git.kernel.org/stable/c/ea0b5d0fe96356dce38f98375a57c52a04e13712
- https://git.kernel.org/stable/c/f0858e1d5624bb120b198f2a8528f97a9b0ae069