Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1325 CNY

100%

CVE-2026-46026— net: qrtr: ns: Limit the maximum number of lookups

AI Predicted 4.7 Difficulty: Easy EPSS 0.13% · P3

Possible ATT&CK Techniques 1AI

T1498 · Network Denial of Service

Affected Version Matrix 18

VendorProductVersion RangeStatus
LinuxLinux0c2204a4ad710d95d348ea006f14ba926e842ffd< bd69e0e8a7643ba5385f19f479e8e3da71f8d495affected
0c2204a4ad710d95d348ea006f14ba926e842ffd< 91cb30b6bb1880ba0748ca059bef50b8ac13793daffected
0c2204a4ad710d95d348ea006f14ba926e842ffd< 6e3675251fcea06caecc61eb76462467558adfa6affected
0c2204a4ad710d95d348ea006f14ba926e842ffd< 0dbec101a7076e9b1e4bd1876f7cf07c56ff4ce3affected
0c2204a4ad710d95d348ea006f14ba926e842ffd< 76adf8f69b0bb3ab20be7c58f5d555027332d113affected
0c2204a4ad710d95d348ea006f14ba926e842ffd< 20855cef7e659ef84ac73251256fa530819b2346affected
0c2204a4ad710d95d348ea006f14ba926e842ffd< 2b930bc77e00cb27e1d6e1d497b3b596283465efaffected
0c2204a4ad710d95d348ea006f14ba926e842ffd< 5640227d9a21c6a8be249a10677b832e7f40dc55affected
… +10 more rows
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-46026

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
net: qrtr: ns: Limit the maximum number of lookups
Source: NVD (National Vulnerability Database)
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: net: qrtr: ns: Limit the maximum number of lookups Current code does no bound checking on the number of lookups a client can perform. Though the code restricts the lookups to local clients, there is still a possibility of a malicious local client sending a flood of NEW_LOOKUP messages over the same socket. Fix this issue by limiting the maximum number of lookups to 64 globally. Since the nameserver allows only atmost one local observer, this global lookup count will ensure that the lookups stay within the limit. Note that, limit of 64 is chosen based on the current platform requirements. If requirement changes in the future, this limit can be increased.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于qrtr命名服务器未限制客户端查找次数,可能导致恶意本地客户端发送大量NEW_LOOKUP消息。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
LinuxLinux 0c2204a4ad710d95d348ea006f14ba926e842ffd ~ bd69e0e8a7643ba5385f19f479e8e3da71f8d495 -
LinuxLinux 5.7 -

II. Public POCs for CVE-2026-46026

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-46026

登录查看更多情报信息。

Patches & Fixes for CVE-2026-46026 (8)

Same Patch Batch · Linux · 2026-05-27 · 275 CVEs total

CVE-2026-459729.8 CRITICALsmb: client: fix potential UAF and double free in smb2_open_file()
CVE-2026-460399.8 CRITICALrxgk: Fix potential integer overflow in length check
CVE-2026-459889.8 CRITICALrxrpc: Fix re-decryption of RESPONSE packets
CVE-2026-458989.8 CRITICALRDMA/iwcm: Fix workqueue list corruption by removing work_list
CVE-2026-460439.1 CRITICALRDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcv
CVE-2026-460568.8 HIGHBluetooth: hci_event: fix potential UAF in SSP passkey handlers
CVE-2026-459458.8 HIGHiommu/vt-d: Fix race condition during PASID entry replacement
CVE-2026-460378.2 HIGHipv4: icmp: validate reply type before using icmp_pointers
CVE-2026-458438.2 HIGHslip: bound decode() reads against the compressed packet length
CVE-2026-460998.1 HIGHnet: ipv6: fix NOREF dst use in seg6 and rpl lwtunnels
CVE-2026-460108.1 HIGHrxrpc: Fix error handling in rxgk_extract_token()
CVE-2026-460767.9 HIGHKVM: nSVM: Raise #UD if unhandled VMMCALL isn't intercepted by L1
CVE-2026-458787.8 HIGHdrm/amdkfd: Fix watch_id bounds checking in debug address watch v2
CVE-2026-459097.8 HIGHclk: mediatek: Drop __initconst from gates
CVE-2026-460367.8 HIGHvfio/cdx: Serialize VFIO_DEVICE_SET_IRQS with a per-device mutex
CVE-2026-459337.8 HIGHbpf: Preserve id of register in sync_linked_regs()
CVE-2026-460657.8 HIGHfbdev: defio: Disconnect deferred I/O from the lifetime of struct fb_info
CVE-2026-460587.8 HIGHmedia: amphion: Fix race between m2m job_abort and device_run
CVE-2026-458947.8 HIGHiommu/vt-d: Clear Present bit before tearing down PASID entry
CVE-2026-460537.8 HIGHnet: rds: fix MR cleanup on copy error

Showing top 20 of 275 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-46026

No comments yet


Leave a comment