CVE-2026-46117

Awaiting Analysis
Published: 28 May 2026, 09:35
Last modified:21 Jul 2026, 12:05

Vulnerability Summary

Overall Risk (default)
medium
31/100
CVSS Score
7.8 HIGH
v3.1 (cve.org)
EPSS Score
0.13% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

28 May 2026, 09:35
Published
Vulnerability first disclosed
21 Jul 2026, 12:05
Last Modified
Vulnerability information updated

Description

In the Linux kernel, the following vulnerability has been resolved: RDMA/mana: Remove user triggerable WARN_ON() in mana_ib_create_qp_rss() Sashiko points out that the user can specify WQs sharing the same CQ as a part of the uAPI and this will trigger the WARN_ON() then go on to corrupt the kernel. Just reject it outright and fail the QP creation.

CVSS Metrics

  • v3.1HIGHScore: 7.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS Trends

Current EPSS score: 0.13% Percentile: 3%

Techniques & Countermeasures

  • CWE-1288Improper Validation of Consistency within Input

    The product receives a complex input with multiple elements or fields that must be consistent with each other, but it does not validate or incorrectly validates that the input is actually consistent.

Affected Systems

  • linuxlinux

    ≥ c15d7802a42402a87880a17eee89ff023e49ecc0, < 9cc0c6b1ba8cd5c55aef043e1384de0a8b4efa71 | ≥ c15d7802a42402a87880a17eee89ff023e49ecc0, < 9ef65af26b2a6738bf15812042e84b3112402d3a | ≥ c15d7802a42402a87880a17eee89ff023e49ecc0, < db991ba50087ad99fa12a2c483aa3be19671ea73 | ≥ c15d7802a42402a87880a17eee89ff023e49ecc0, < 159f2efabc89d3f931d38f2d35876535d4abf0a3 | 6.8

References (11)