Skip to main content

Threats Tagged 'cve-2026-46209'

View all threats tagged with 'cve-2026-46209'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cve-2026-46209

Threats Tagged 'cve-2026-46209'

Click on any threat for detailed analysis and mitigation recommendations

The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: Bluetooth: SCO: fix race conditions in sco_sock_connect() (CVE-2026-43023) * kernel: drm/gem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_funcs() (CVE-2026-46209) Bug Fix(es) and Enhancement(s): * [RHEL 10] Bonding reports unknown speed/duplex for tg3 interface [rhel-10.0.z] (JIRA:RHEL-182769) * CLONE -RHEL 10.0.z xfs: fix exchange-range reflink flag clearing issue with INO1_WRITTEN (JIRA:RHEL-224218) * vhost: reset the vring metadata cache on vring reconfiguration [rhel-10.0.z] (JIRA:RHEL-224544) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Join the discussion

Red Hat has released a security advisory addressing multiple vulnerabilities in the Linux kernel packages for Red Hat Enterprise Linux 9.6 Extended Update Support. The update fixes several security issues including use-after-free bugs, information leaks, out-of-bounds reads, and validation errors across various kernel components such as VMCI, virtual terminal, Bluetooth, AMD display, SMB client, network scheduler, and DRM. The advisory also includes bug fixes and enhancements unrelated to security. Systems must be rebooted after applying the update for changes to take effect.

Join the discussion
0

The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: ima: don't clear IMA_DIGSIG flag when setting or removing non-IMA xattr (CVE-2025-68183) * kernel: Bluetooth: SCO: Fix use-after-free in sco_recv_frame() due to missing sock_hold (CVE-2026-31408) * kernel: tcp: fix potential race in tcp_v6_syn_recv_sock() (CVE-2026-43198) * kernel: RDMA/vmw_pvrdma: Fix double free on pvrdma_alloc_ucontext() error path (CVE-2026-46189) * kernel: nvmet-tcp: fix race between ICReq handling and queue teardown (CVE-2026-46135) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Join the discussion
0

The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements. Security Fix(es): * kernel: ima: don't clear IMA_DIGSIG flag when setting or removing non-IMA xattr (CVE-2025-68183) * kernel: Bluetooth: SCO: Fix use-after-free in sco_recv_frame() due to missing sock_hold (CVE-2026-31408) * kernel: tcp: fix potential race in tcp_v6_syn_recv_sock() (CVE-2026-43198) * kernel: RDMA/vmw_pvrdma: Fix double free on pvrdma_alloc_ucontext() error path (CVE-2026-46189) * kernel: nvmet-tcp: fix race between ICReq handling and queue teardown (CVE-2026-46135) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Join the discussion

The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: drm/amd/display: Do not skip unrelated mode changes in DSC validation (CVE-2026-31488) * kernel: ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach() (CVE-2026-43038) * kernel: netfilter: flowtable: strictly check for maximum number of actions (CVE-2026-43329) * kernel: ALSA: aloop: Fix peer runtime UAF during format-change stop (CVE-2026-46090) * kernel: selinux: fix overlayfs mmap() and mprotect() access checks (CVE-2026-46054) * kernel: RDMA/iwcm: Fix workqueue list corruption by removing work_list (CVE-2026-45898) * kernel: RDMA/vmw_pvrdma: Fix double free on pvrdma_alloc_ucontext() error path (CVE-2026-46189) * kernel: RDMA/mlx5: Fix error path fall-through in mlx5_ib_dev_res_srq_init() (CVE-2026-46176) Bug Fix(es) and Enhancement(s): * [RHEL-9.8.z]: Update the mlx5 drivers to v6.19 (JIRA:RHEL-169057) * iavf: during POD churn vlan filters may not be added for a vlan interface, spoofchk drops subsequent packets [rhel-9.8.z] (JIRA:RHEL-172993) * nf_conntrack_sctp: vtag corruption with late INIT in ESTABLISHED state across conntrack zones [rhel-9.8.z] (JIRA:RHEL-178273) * sched/fair: Skip sched_balance_running cmpxchg when balance is not due [rhel-9.8.z] (JIRA:RHEL-182776) * [REGRESSION] ISST-Spyre: Jenkins workload causes soft lock warning to appear on screen. Workload hangs. [rhel-9.8.z] (JIRA:RHEL-183183) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Join the discussion

The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: drm/amd/display: Do not skip unrelated mode changes in DSC validation (CVE-2026-31488) * kernel: ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach() (CVE-2026-43038) * kernel: netfilter: flowtable: strictly check for maximum number of actions (CVE-2026-43329) * kernel: ALSA: aloop: Fix peer runtime UAF during format-change stop (CVE-2026-46090) * kernel: selinux: fix overlayfs mmap() and mprotect() access checks (CVE-2026-46054) * kernel: RDMA/iwcm: Fix workqueue list corruption by removing work_list (CVE-2026-45898) * kernel: RDMA/vmw_pvrdma: Fix double free on pvrdma_alloc_ucontext() error path (CVE-2026-46189) * kernel: RDMA/mlx5: Fix error path fall-through in mlx5_ib_dev_res_srq_init() (CVE-2026-46176) Bug Fix(es) and Enhancement(s): * [RHEL-9.8.z]: Update the mlx5 drivers to v6.19 (JIRA:RHEL-169057) * iavf: during POD churn vlan filters may not be added for a vlan interface, spoofchk drops subsequent packets [rhel-9.8.z] (JIRA:RHEL-172993) * nf_conntrack_sctp: vtag corruption with late INIT in ESTABLISHED state across conntrack zones [rhel-9.8.z] (JIRA:RHEL-178273) * sched/fair: Skip sched_balance_running cmpxchg when balance is not due [rhel-9.8.z] (JIRA:RHEL-182776) * [REGRESSION] ISST-Spyre: Jenkins workload causes soft lock warning to appear on screen. Workload hangs. [rhel-9.8.z] (JIRA:RHEL-183183) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Join the discussion

In the Linux kernel, the following vulnerability has been resolved: drm/gem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_funcs() drm_gem_fb_init_with_funcs() computes sub-sampled plane dimensions using plain integer division: unsigned int width = mode_cmd->width / (i ? info->hsub : 1); unsigned int height = mode_cmd->height / (i ? info->vsub : 1); However, the ioctl-level framebuffer_check() in drm_framebuffer.c uses drm_format_info_plane_width/height() which round up dimensions via DIV_ROUND_UP(). This inconsistency corrupts the subsequent GEM object size check for certain pixel format and dimension combinations. For example, with NV12 (vsub=2) and a 1-pixel-tall framebuffer the GEM size validation path sees height=0 instead of height=1. The expression (height - 1) then wraps to UINT_MAX as an unsigned int, causing min_size to overflow and wrap back to a small value. A tiny GEM object therefore passes the size guard, yet when the GPU accesses the chroma plane it will read or write memory beyond the object's bounds. Fix by replacing the open-coded divisions with drm_format_info_plane_width() and drm_format_info_plane_height(), which use DIV_ROUND_UP() and match the calculation already used in framebuffer_check().

Join the discussion

To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle

Join the discussion

Showing 1 to 8 of 8 results

Filters:Tag: cve-2026-46209
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses