Incorrect calculation in Linux kernel - CVE-2026-46193

 

Incorrect calculation in Linux kernel - CVE-2026-46193

Published: May 29, 2026


Vulnerability identifier: #VU133009
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-46193
CWE-ID: CWE-682
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper handling of ESN high bits in async callbacks in the AH implementation when processing AH packets with ESN enabled using an asynchronous AH implementation. A local user can send specially crafted AH traffic to cause a denial of service.

The issue affects both IPv4 and IPv6 AH paths, and exploitation requires ESN to be enabled with an asynchronous AH implementation selected.


Affected software

Linux kernel
openEuler
Ubuntu
bpftool
kernel
python3-perf-debuginfo
python3-perf
perf-debuginfo
perf
kernel-tools-devel
kernel-tools-debuginfo
kernel-tools
kernel-source
kernel-headers
kernel-devel
kernel-debugsource
kernel-debuginfo
bpftool-debuginfo
linux (Ubuntu package)
linux-fips (Ubuntu package)
linux-hwe-6.8 (Ubuntu package)
linux-ibm (Ubuntu package)
linux-oracle-6.8 (Ubuntu package)
linux-nvidia (Ubuntu package)
linux-aws-6.8 (Ubuntu package)
linux-aws (Ubuntu package)
linux-raspi (Ubuntu package)
linux-azure-fde (Ubuntu package)
linux-azure-fde-6.8 (Ubuntu package)
linux-azure (Ubuntu package)
linux-azure-fips (Ubuntu package)
linux-gcp-fips (Ubuntu package)
linux-oem-7.0 (Ubuntu package)
linux-nvidia-bos (Ubuntu package)

How to mitigate CVE-2026-46193

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3
bpftool - update to 5.10.0-320.0.0.222
kernel - update to 5.10.0-320.0.0.222
python3-perf-debuginfo - update to 5.10.0-320.0.0.222
python3-perf - update to 5.10.0-320.0.0.222
perf-debuginfo - update to 5.10.0-320.0.0.222
perf - update to 5.10.0-320.0.0.222
kernel-tools-devel - update to 5.10.0-320.0.0.222
kernel-tools-debuginfo - update to 5.10.0-320.0.0.222
kernel-tools - update to 5.10.0-320.0.0.222
kernel-source - update to 5.10.0-320.0.0.222
kernel-headers - update to 5.10.0-320.0.0.222
kernel-devel - update to 5.10.0-320.0.0.222
kernel-debugsource - update to 5.10.0-320.0.0.222
kernel-debuginfo - update to 5.10.0-320.0.0.222
bpftool-debuginfo - update to 5.10.0-320.0.0.222
linux (Ubuntu package) - addressed in versions 6.8.0-136.136, 6.8.0-1046.50, 6.8.0-1059.67, 6.8.0-1064.72, 6.8.0-1064.72~22.04.1, 6.8.1-1056.57, 6.8.1-1056.57~22.04.2, 7.0.0-28.28, 7.0.0-28.28.1, 7.0.0-1003.4, 7.0.0-1008.8
linux-fips (Ubuntu package) - addressed in versions 6.8.0-136.136+fips2, 6.8.0-136.136.2, 6.8.0-136.136.2~22.04.1, 6.8.0-1058.61
linux-hwe-6.8 (Ubuntu package) - update to 6.8.0-136.136~22.04.1
linux-ibm (Ubuntu package) - addressed in versions 6.8.0-1030.31, 6.8.0-1033.34, 6.8.0-1061.62, 6.8.0-1061.62~22.04.1, 7.0.0-1008.8, 7.0.0-1010.10
linux-oracle-6.8 (Ubuntu package) - update to 6.8.0-1058.61~22.04.1
linux-nvidia (Ubuntu package) - addressed in versions 6.8.0-1059.62, 6.8.0-1059.62.1, 6.8.0-1059.62~22.04.1, 7.0.0-1016.16, 7.0.0-1016.16~24.04.1
linux-aws-6.8 (Ubuntu package) - addressed in versions 6.8.0-1061.64+fips1, 6.8.0-1061.64~22.04.1
linux-aws (Ubuntu package) - addressed in versions 6.8.0-1061.64+1, 7.0.0-1009.9, 7.0.0-1015.15
linux-raspi (Ubuntu package) - addressed in versions 6.8.0-1061.65, 6.8.0-2050.52
linux-azure-fde (Ubuntu package) - update to 6.8.0-1062.69
linux-azure-fde-6.8 (Ubuntu package) - update to 6.8.0-1062.69~22.04.1
linux-azure (Ubuntu package) - addressed in versions 6.8.0-1063.71, 6.8.0-1063.71~22.04.1, 7.0.0-1009.9, 7.0.0-1010.10
linux-azure-fips (Ubuntu package) - update to 6.8.0-1063.71+fips2
linux-gcp-fips (Ubuntu package) - update to 6.8.0-1064.72+fips1
linux-oem-7.0 (Ubuntu package) - update to 7.0.0-1009.9
linux-nvidia-bos (Ubuntu package) - update to 7.0.0-2016.16

External References

Related Security Bulletins