Incorrect calculation in Linux kernel - CVE-2026-46325
Published: June 10, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper memory address conversion in the RDMA RXE memory region handling code when processing memory regions with page sizes different from the system PAGE_SIZE. A local user can register or access a crafted memory region layout to cause a denial of service.
The issue can lead to incorrect iova-to-va translation and a kernel panic.
Affected software
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Ubuntu
Anolis OS
kernel (Red Hat package)
bpftool
kernel
kernel-debug
kernel-debug-devel
kernel-devel
kernel-headers
kernel-tools
kernel-tools-libs
kernel-tools-libs-devel
perf
python3-perf
linux (Ubuntu package)
linux-lowlatency (Ubuntu package)
linux-hwe-6.8 (Ubuntu package)
linux-oracle-6.8 (Ubuntu package)
linux-aws-6.8 (Ubuntu package)
linux-raspi (Ubuntu package)
linux-hwe-6.17 (Ubuntu package)
linux-azure-fde-6.17 (Ubuntu package)
linux-azure-6.17 (Ubuntu package)
linux-nvidia-6.17 (Ubuntu package)
linux-oem-6.17 (Ubuntu package)
How to mitigate CVE-2026-46325
kernel (Red Hat package) - update to 5.14.0-687.53.1.el9_8
bpftool - update to 6.6.102-7
kernel - update to 6.6.102-7
kernel-debug - update to 6.6.102-7
kernel-debug-devel - update to 6.6.102-7
kernel-devel - update to 6.6.102-7
kernel-headers - update to 6.6.102-7
kernel-tools - update to 6.6.102-7
kernel-tools-libs - update to 6.6.102-7
kernel-tools-libs-devel - update to 6.6.102-7
perf - update to 6.6.102-7
python3-perf - update to 6.6.102-7
linux (Ubuntu package) - addressed in versions 6.8.0-137.137+fips1, 6.8.0-1034.35, 6.8.0-1047.51, 6.8.0-1060.63.1, 6.8.0-1060.63~22.04.1, 6.8.0-1060.68, 6.8.0-1062.63, 6.8.0-1062.63~22.04.1, 6.8.0-1062.65, 6.8.0-1062.65+fips1, 6.8.0-1063.70, 6.8.0-1063.70~22.04.1, 6.8.0-1064.72+fips1, 6.8.0-1064.72~22.04.1, 6.8.0-1065.73, 6.8.0-1065.73+fips1, 6.8.0-1065.73~22.04.1, 6.8.1-1057.58, 6.8.1-1057.58~22.04.1, 6.17.0-40.40
linux-lowlatency (Ubuntu package) - addressed in versions 6.8.0-137.137.1, 6.8.0-137.137.1~22.04.1, 6.8.0-1031.32, 6.8.0-1059.62
linux-hwe-6.8 (Ubuntu package) - update to 6.8.0-138.138~22.04.1
linux-oracle-6.8 (Ubuntu package) - update to 6.8.0-1059.62~22.04.1
linux-aws-6.8 (Ubuntu package) - update to 6.8.0-1062.65~22.04.1
linux-raspi (Ubuntu package) - addressed in versions 6.8.0-1062.66, 6.8.0-2051.53, 6.17.0-1021.21
linux-hwe-6.17 (Ubuntu package) - update to 6.17.0-40.40~24.04.1
linux-azure-fde-6.17 (Ubuntu package) - update to 6.17.0-1018.18~24.04.1
linux-azure-6.17 (Ubuntu package) - update to 6.17.0-1021.21~24.04.1
linux-nvidia-6.17 (Ubuntu package) - update to 6.17.0-1026.26
linux-oem-6.17 (Ubuntu package) - update to 6.17.0-1028.28
External References
Related Security Bulletins
- Incorrect calculation in Linux kernel sw rxe driver
- Ubuntu update for linux-oem-6.17
- Ubuntu update for linux
- Ubuntu update for linux-nvidia-6.17
- Ubuntu update for linux-raspi
- Ubuntu update for linux-hwe-6.17
- Ubuntu update for linux-raspi
- Ubuntu update for linux-azure-fde-6.17
- Ubuntu update for linux-azure-6.17
- Ubuntu update for linux
- Ubuntu update for linux-lowlatency
- Anolis OS update for kernel:6.6
- Ubuntu update for linux-oracle-6.8
- Ubuntu update for linux-hwe-6.8
- Ubuntu update for linux-aws-6.8
- Ubuntu update for linux-raspi
- Red Hat Enterprise Linux 9 update for kernel