BlackTreeIndependent security intelligence
← Back to the CVE catalogue
Full vulnerability report · 2026
CVE-2026-46124High confidence

isofs: validate block number from NFS file handle in isofs_export_iget

Linux · Linux

7.5HighCVSS 3.1
Recommended action
Within 7 days

High technical severity; prioritise exposed affected systems while verifying vendor guidance.

Patch available
Distribution package intelligence

Ubuntu vendor package status

Canonical’s release and source-package findings are shown separately from local repository availability.

20 package states
Repository candidate not checked

A published vendor fix does not prove that a matching update is enabled and installable on a particular asset. Confirm the local package candidate before scheduling remediation.

Ubuntu releaseSource packageVendor stateFixed versionEvidence
Ubuntu 24.04 LTSnoble · standard archivelinuxAffected, no fix publishedCanonical OVAL identifies this running kernel flavour as affected and does not publish a fixed package version in this definition.Not published in this feedCanonical record ↗Source updated 9 Sept 2026
Ubuntu 24.04 LTSnoble · standard archivelinux-awsAffected, no fix publishedCanonical OVAL identifies this running kernel flavour as affected and does not publish a fixed package version in this definition.Not published in this feedCanonical record ↗Source updated 9 Sept 2026
Ubuntu 24.04 LTSnoble · standard archivelinux-azureAffected, no fix publishedCanonical OVAL identifies this running kernel flavour as affected and does not publish a fixed package version in this definition.Not published in this feedCanonical record ↗Source updated 9 Sept 2026
Ubuntu 24.04 LTSnoble · standard archivelinux-azure-fdeAffected, no fix publishedCanonical OVAL identifies this running kernel flavour as affected and does not publish a fixed package version in this definition.Not published in this feedCanonical record ↗Source updated 9 Sept 2026
Ubuntu 24.04 LTSnoble · standard archivelinux-azure-nvidiaAffected, no fix publishedCanonical OVAL identifies this running kernel flavour as affected and does not publish a fixed package version in this definition.Not published in this feedCanonical record ↗Source updated 9 Sept 2026
Ubuntu 24.04 LTSnoble · standard archivelinux-gcpAffected, no fix publishedCanonical OVAL identifies this running kernel flavour as affected and does not publish a fixed package version in this definition.Not published in this feedCanonical record ↗Source updated 9 Sept 2026
Ubuntu 24.04 LTSnoble · standard archivelinux-gkeAffected, no fix publishedCanonical OVAL identifies this running kernel flavour as affected and does not publish a fixed package version in this definition.Not published in this feedCanonical record ↗Source updated 9 Sept 2026
Ubuntu 24.04 LTSnoble · standard archivelinux-gkeopAffected, no fix publishedCanonical OVAL identifies this running kernel flavour as affected and does not publish a fixed package version in this definition.Not published in this feedCanonical record ↗Source updated 9 Sept 2026
Ubuntu 24.04 LTSnoble · standard archivelinux-ibmAffected, no fix publishedCanonical OVAL identifies this running kernel flavour as affected and does not publish a fixed package version in this definition.Not published in this feedCanonical record ↗Source updated 9 Sept 2026
Ubuntu 24.04 LTSnoble · standard archivelinux-lowlatencyAffected, no fix publishedCanonical OVAL identifies this running kernel flavour as affected and does not publish a fixed package version in this definition.Not published in this feedCanonical record ↗Source updated 9 Sept 2026
Ubuntu 24.04 LTSnoble · standard archivelinux-nvidiaAffected, no fix publishedCanonical OVAL identifies this running kernel flavour as affected and does not publish a fixed package version in this definition.Not published in this feedCanonical record ↗Source updated 9 Sept 2026
Ubuntu 24.04 LTSnoble · standard archivelinux-nvidia-lowlatencyAffected, no fix publishedCanonical OVAL identifies this running kernel flavour as affected and does not publish a fixed package version in this definition.Not published in this feedCanonical record ↗Source updated 9 Sept 2026
Ubuntu 24.04 LTSnoble · standard archivelinux-nvidia-tegraAffected, no fix publishedCanonical OVAL identifies this running kernel flavour as affected and does not publish a fixed package version in this definition.Not published in this feedCanonical record ↗Source updated 9 Sept 2026
Ubuntu 24.04 LTSnoble · standard archivelinux-oem-6.11Affected, no fix publishedCanonical OVAL identifies this running kernel flavour as affected and does not publish a fixed package version in this definition.Not published in this feedCanonical record ↗Source updated 9 Sept 2026
Ubuntu 24.04 LTSnoble · standard archivelinux-oracleAffected, no fix publishedCanonical OVAL identifies this running kernel flavour as affected and does not publish a fixed package version in this definition.Not published in this feedCanonical record ↗Source updated 9 Sept 2026
Ubuntu 24.04 LTSnoble · standard archivelinux-raspiAffected, no fix publishedCanonical OVAL identifies this running kernel flavour as affected and does not publish a fixed package version in this definition.Not published in this feedCanonical record ↗Source updated 9 Sept 2026
Ubuntu 24.04 LTSnoble · standard archivelinux-raspi-realtimeAffected, no fix publishedCanonical OVAL identifies this running kernel flavour as affected and does not publish a fixed package version in this definition.Not published in this feedCanonical record ↗Source updated 9 Sept 2026
Ubuntu 24.04 LTSnoble · standard archivelinux-realtimeAffected, no fix publishedCanonical OVAL identifies this running kernel flavour as affected and does not publish a fixed package version in this definition.Not published in this feedCanonical record ↗Source updated 9 Sept 2026
Ubuntu 24.04 LTSnoble · standard archivelinux-riscvAffected, no fix publishedCanonical OVAL identifies this running kernel flavour as affected and does not publish a fixed package version in this definition.Not published in this feedCanonical record ↗Source updated 9 Sept 2026
Ubuntu 24.04 LTSnoble · standard archivelinux-xilinxAffected, no fix publishedCanonical OVAL identifies this running kernel flavour as affected and does not publish a fixed package version in this definition.Not published in this feedCanonical record ↗Source updated 9 Sept 2026
Optional official sources

National CERT insights
?CERT means Computer Emergency Response Team; CSIRT is the closely related term Computer Security Incident Response Team.

Select the national-authority views to include. The exact source language is shown on each matched advisory. Your choice is remembered on this device and encoded in the shareable URL.

Official European source

ENISA European Vulnerability Database

Official EUVD identifiers, advisory evidence and known-exploited context. Missing fields are not treated as evidence of low risk.

1 current
ENISA EUVD identifier

EUVD-2026-32883

No EUVD known-exploited evidence

ENISA has published the identifier mapping but no EUVD description has been stored yet.

EUVD state
Present in the current official mapping
Known exploitation
Not present in the current ENISA EUVD known-exploited dataset. This is not proof of no exploitation.
ENISA score
Not supplied in the stored EUVD record
Advisory evidence
No linked advisory details stored yet
Recommended actionWithin 7 days

High technical severity; prioritise exposed affected systems while verifying vendor guidance.

Patch available
01

What, why and how

In the Linux kernel, the following vulnerability has been resolved: isofs: validate block number from NFS file handle in isofs_export_iget isofs_fh_to_dentry() and isofs_fh_to_parent() pass an attacker- controlled block number (ifid->block or ifid->parent_block) from the NFS file handle to isofs_export_iget(), which only rejects block == 0 before calling isofs_iget() and ultimately sb_bread(). A crafted file handle with fh_len sufficient to pass the check added by commit 0405d4b63d08 ("isofs: Prevent the use of too small fid") can still drive the server to read any in-range block on the backing device as if it were an iso_directory_record. That earlier fix was assigned CVE-2025-37780. sb_bread() on an out-of-range block returns NULL cleanly via the EIO path, so there is no memory-safety violation. For in-range reads of adjacent-partition data on the same block device, the unrelated bytes end up in iso_inode_info fields that reach the NFS client as dentry metadata. The deployment surface (isofs exported over NFS from loop-mounted images) is narrow and requires an authenticated NFS peer, but the malformed-file-handle class is reportable as hardening next to the existing CVE-2025-37780 fix. Reject block >= ISOFS_SB(sb)->s_nzones in isofs_export_iget() so the check covers both isofs_fh_to_dentry() and isofs_fh_to_parent() call sites with a single line.

What

In the Linux kernel, the following vulnerability has been resolved: isofs: validate block number from NFS file handle in isofs_export_iget isofs_fh_to_dentry() and isofs_fh_to_parent() pass an attacker- controlled block number (ifid->block or ifid->parent_block) from the NFS file handle to isofs_export_iget(), which only rejects block == 0 before calling isofs_iget() and ultimately sb_bread(). A crafted file handle with fh_len sufficient to pass the check added by commit 0405d4b63d08 ("isofs: Prevent the use of too small fid") can still drive the server to read any in-range block on the backing device as if it were an iso_directory_record. That earlier fix was assigned CVE-2025-37780. sb_bread() on an out-of-range block returns NULL cleanly via the EIO path, so there is no memory-safety violation. For in-range reads of adjacent-partition data on the same block device, the unrelated bytes end up in iso_inode_info fields that reach the NFS client as dentry metadata. The deployment surface (isofs exported over NFS from loop-mounted images) is narrow and requires an authenticated NFS peer, but the malformed-file-handle class is reportable as hardening next to the existing CVE-2025-37780 fix. Reject block >= ISOFS_SB(sb)->s_nzones in isofs_export_iget() so the check covers both isofs_fh_to_dentry() and isofs_fh_to_parent() call sites with a single line.

Why

The current structured CVE record identifies a security weakness, but the root cause requires confirmation in the linked vendor material.

How

An attacker operating through a network path may attempt exploitation without authentication or user interaction. If successful, the issue may cause the confidentiality, integrity or availability impact described by the vendor.

What

In the Linux kernel, the following vulnerability has been resolved: isofs: validate block number from NFS file handle in isofs_export_iget isofs_fh_to_dentry() and isofs_fh_to_parent() pass an attacker- controlled block number (ifid->block or ifid->parent_block) from the NFS file handle to isofs_export_iget(), which only rejects block == 0 before calling isofs_iget() and ultimately sb_bread(). A crafted file handle with fh_len sufficient to pass the check added by commit 0405d4b63d08 ("isofs: Prevent the use of too small fid") can still drive the server to read any in-range block on the backing device as if it were an iso_directory_record. That earlier fix was assigned CVE-2025-37780. sb_bread() on an out-of-range block returns NULL cleanly via the EIO path, so there is no memory-safety violation. For in-range reads of adjacent-partition data on the same block device, the unrelated bytes end up in iso_inode_info fields that reach the NFS client as dentry metadata. The deployment surface (isofs exported over NFS from loop-mounted images) is narrow and requires an authenticated NFS peer, but the malformed-file-handle class is reportable as hardening next to the existing CVE-2025-37780 fix. Reject block >= ISOFS_SB(sb)->s_nzones in isofs_export_iget() so the check covers both isofs_fh_to_dentry() and isofs_fh_to_parent() call sites with a single line.

Why

The current structured CVE record identifies a security weakness, but the root cause requires confirmation in the linked vendor material.

How

An attacker operating through a network path may attempt exploitation without authentication or user interaction. If successful, the issue may cause the confidentiality, integrity or availability impact described by the vendor.

02

Exploit reality and attack path

CVSS severity, EPSS forecast probability, public exploit material and CISA-confirmed exploitation are separate signals.

Observed exploitation
?Confirmed exploitation and public exploit material are separate signals. Attacks can occur without public proof-of-concept or exploit code.
No confirmed evidence

No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.

Public PoC / exploit material
?Confirmed exploitation and public exploit material are separate signals. Attacks can occur without public proof-of-concept or exploit code.
None recorded

No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.

Likely attack path
a network path → vulnerable operation → cause the confidentiality, integrity or availability impact described by the vendor
Attack surface
Network
Privileges required
None: unauthenticated exploitation is possible
User interaction
None
Attack complexity
Low: no specialised conditions are recorded
Security boundary
Unchanged: impact remains within the vulnerable component's security authority
Weakness
?CWE means Common Weakness Enumeration.
CWE not yet assigned
CVSS vector
?CVSS means Common Vulnerability Scoring System. The vector records the metric values used to calculate technical severity.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Common Vulnerability Scoring System 3.1: the compact vector below is decoded into plain language.

AVNetworkAttack vector: The vulnerable component can be reached over a network.ACLowAttack complexity: No specialised conditions are required beyond attacker-controlled input.PRNonePrivileges required: The attacker does not need an account or existing privileges.UINoneUser interaction: No action by another user is required.SUnchangedScope: The security impact remains within the vulnerable component's authority.CHighConfidentiality impact: A successful attack can cause a major loss.INoneIntegrity impact: No direct loss is represented by this metric.ANoneAvailability impact: No direct loss is represented by this metric.
Post-exploitation / living off the land
No specific living-off-the-land technique is confirmed in the structured sources. Monitor normal administration tools for activity inconsistent with the affected service's baseline.
NetworkUnauthenticated
A

Official authority intelligence

Only matched European and national findings are included. Language selectors and unavailable sources are omitted.

BSI · German · WID-SEC-W-2026-1700Linux Kernel: Mehrere Schwachstellen

Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen oder andere nicht näher spezifizierte Auswirkungen zu erzielen.

Official advisory
CERT-FR · French · CERTFR-2026-AVI-1093Multiples vulnérabilités dans le noyau Linux d'Ubuntu

d?id=CVE-2026-46102 Référence CVE CVE-2026-46107 https://www.cve.org/CVERecord?id=CVE-2026-46107 Référence CVE CVE-2026-46108 https://www.cve.org/CVERecord?id=CVE-2026-46108 Référence CVE CVE-2026-46112 https://www.cve.org/CVERecord?id=CVE-2026-46112 Référence CVE CVE-2026-46113 https://www.cve.org/CVERecord?id=CVE-2026-46113 Référence CVE CVE-2026-46119 https://www.cve.org/CVERecord?id=CVE-2026-46119 Référence CVE CVE-2026-46120 https://www.cve.org/CVERecord?id=CVE-2026-46120 Référence CVE CVE-2026-46122 https://www.cve.org/CVERecord?id=CVE-2026-46122 Référence CVE CVE-2026-46123 https://www.cve.org/CVERecord?id=CVE-2026-46123 Référence CVE CVE-2026-46124 https://www.cve.org/CVERecord?id=CVE-2026-46124 Référence CVE CVE-2026-46127 https://www.cve.org/CVERecord?id=CVE-2026-46127 Référence CVE CVE-2026-46128 https://www.cve.org/CVERecord?id=CVE-2026-46128 Référence CVE CVE-2026-46132 https://www.cve.org/CVERecord?id=CVE-2026-46132 Référence CVE CVE-2026-46133 https://www.cve.org/CVERecord?id=CVE-2026-46133 Référence CVE CVE-2026-46135 https://www.cve.org/CVERecord?id=CVE-2026-46135 Référence CVE CVE-2026-46137 https://www.cve.org/CVERecord?id=CVE-2026-46137 Référence CVE CVE-2026-46146 https://www.cve.org/CVERecord?id=CVE-2026-46146 Référence CVE CVE-2026-46149 https://www.cve.org/CVERecord?id=

Official advisory
CERT-FR · French · CERTFR-2026-AVI-1066Multiples vulnérabilités dans le noyau Linux d'Ubuntu

d?id=CVE-2026-46113 Référence CVE CVE-2026-46114 https://www.cve.org/CVERecord?id=CVE-2026-46114 Référence CVE CVE-2026-46116 https://www.cve.org/CVERecord?id=CVE-2026-46116 Référence CVE CVE-2026-46117 https://www.cve.org/CVERecord?id=CVE-2026-46117 Référence CVE CVE-2026-46118 https://www.cve.org/CVERecord?id=CVE-2026-46118 Référence CVE CVE-2026-46120 https://www.cve.org/CVERecord?id=CVE-2026-46120 Référence CVE CVE-2026-46121 https://www.cve.org/CVERecord?id=CVE-2026-46121 Référence CVE CVE-2026-46122 https://www.cve.org/CVERecord?id=CVE-2026-46122 Référence CVE CVE-2026-46123 https://www.cve.org/CVERecord?id=CVE-2026-46123 Référence CVE CVE-2026-46124 https://www.cve.org/CVERecord?id=CVE-2026-46124 Référence CVE CVE-2026-46125 https://www.cve.org/CVERecord?id=CVE-2026-46125 Référence CVE CVE-2026-46126 https://www.cve.org/CVERecord?id=CVE-2026-46126 Référence CVE CVE-2026-46127 https://www.cve.org/CVERecord?id=CVE-2026-46127 Référence CVE CVE-2026-46128 https://www.cve.org/CVERecord?id=CVE-2026-46128 Référence CVE CVE-2026-46129 https://www.cve.org/CVERecord?id=CVE-2026-46129 Référence CVE CVE-2026-46130 https://www.cve.org/CVERecord?id=CVE-2026-46130 Référence CVE CVE-2026-46131 https://www.cve.org/CVERecord?id=CVE-2026-46131 Référence CVE CVE-2026-46132 https://www.cve.org/CVERecord?id=

Official advisory
CERT-FR · French · CERTFR-2026-AVI-0985Multiples vulnérabilités dans le noyau Linux d'Ubuntu

d?id=CVE-2026-46099 Référence CVE CVE-2026-46101 https://www.cve.org/CVERecord?id=CVE-2026-46101 Référence CVE CVE-2026-46102 https://www.cve.org/CVERecord?id=CVE-2026-46102 Référence CVE CVE-2026-46107 https://www.cve.org/CVERecord?id=CVE-2026-46107 Référence CVE CVE-2026-46108 https://www.cve.org/CVERecord?id=CVE-2026-46108 Référence CVE CVE-2026-46112 https://www.cve.org/CVERecord?id=CVE-2026-46112 Référence CVE CVE-2026-46120 https://www.cve.org/CVERecord?id=CVE-2026-46120 Référence CVE CVE-2026-46122 https://www.cve.org/CVERecord?id=CVE-2026-46122 Référence CVE CVE-2026-46123 https://www.cve.org/CVERecord?id=CVE-2026-46123 Référence CVE CVE-2026-46124 https://www.cve.org/CVERecord?id=CVE-2026-46124 Référence CVE CVE-2026-46127 https://www.cve.org/CVERecord?id=CVE-2026-46127 Référence CVE CVE-2026-46128 https://www.cve.org/CVERecord?id=CVE-2026-46128 Référence CVE CVE-2026-46132 https://www.cve.org/CVERecord?id=CVE-2026-46132 Référence CVE CVE-2026-46133 https://www.cve.org/CVERecord?id=CVE-2026-46133 Référence CVE CVE-2026-46137 https://www.cve.org/CVERecord?id=CVE-2026-46137 Référence CVE CVE-2026-46146 https://www.cve.org/CVERecord?id=CVE-2026-46146 Référence CVE CVE-2026-46149 https://www.cve.org/CVERecord?id=CVE-2026-46149 Référence CVE CVE-2026-46150 https://www.cve.org/CVERecord?id=

Official advisory
CERT-FR · French · CERTFR-2026-AVI-0956Multiples vulnérabilités dans le noyau Linux de SUSE

d?id=CVE-2026-46093 Référence CVE CVE-2026-46099 https://www.cve.org/CVERecord?id=CVE-2026-46099 Référence CVE CVE-2026-46101 https://www.cve.org/CVERecord?id=CVE-2026-46101 Référence CVE CVE-2026-46111 https://www.cve.org/CVERecord?id=CVE-2026-46111 Référence CVE CVE-2026-46112 https://www.cve.org/CVERecord?id=CVE-2026-46112 Référence CVE CVE-2026-46113 https://www.cve.org/CVERecord?id=CVE-2026-46113 Référence CVE CVE-2026-46116 https://www.cve.org/CVERecord?id=CVE-2026-46116 Référence CVE CVE-2026-46119 https://www.cve.org/CVERecord?id=CVE-2026-46119 Référence CVE CVE-2026-46120 https://www.cve.org/CVERecord?id=CVE-2026-46120 Référence CVE CVE-2026-46124 https://www.cve.org/CVERecord?id=CVE-2026-46124 Référence CVE CVE-2026-46150 https://www.cve.org/CVERecord?id=CVE-2026-46150 Référence CVE CVE-2026-46160 https://www.cve.org/CVERecord?id=CVE-2026-46160 Référence CVE CVE-2026-46161 https://www.cve.org/CVERecord?id=CVE-2026-46161 Référence CVE CVE-2026-46162 https://www.cve.org/CVERecord?id=CVE-2026-46162 Référence CVE CVE-2026-46172 https://www.cve.org/CVERecord?id=CVE-2026-46172 Référence CVE CVE-2026-46173 https://www.cve.org/CVERecord?id=CVE-2026-46173 Référence CVE CVE-2026-46178 https://www.cve.org/CVERecord?id=CVE-2026-46178 Référence CVE CVE-2026-46185 https://www.cve.org/CVERecord?id=

Official advisory
CERT-FR · French · CERTFR-2026-AVI-0954Multiples vulnérabilités dans le noyau Linux d'Ubuntu

d?id=CVE-2026-46115 Référence CVE CVE-2026-46116 https://www.cve.org/CVERecord?id=CVE-2026-46116 Référence CVE CVE-2026-46117 https://www.cve.org/CVERecord?id=CVE-2026-46117 Référence CVE CVE-2026-46118 https://www.cve.org/CVERecord?id=CVE-2026-46118 Référence CVE CVE-2026-46119 https://www.cve.org/CVERecord?id=CVE-2026-46119 Référence CVE CVE-2026-46120 https://www.cve.org/CVERecord?id=CVE-2026-46120 Référence CVE CVE-2026-46121 https://www.cve.org/CVERecord?id=CVE-2026-46121 Référence CVE CVE-2026-46122 https://www.cve.org/CVERecord?id=CVE-2026-46122 Référence CVE CVE-2026-46123 https://www.cve.org/CVERecord?id=CVE-2026-46123 Référence CVE CVE-2026-46124 https://www.cve.org/CVERecord?id=CVE-2026-46124 Référence CVE CVE-2026-46125 https://www.cve.org/CVERecord?id=CVE-2026-46125 Référence CVE CVE-2026-46126 https://www.cve.org/CVERecord?id=CVE-2026-46126 Référence CVE CVE-2026-46127 https://www.cve.org/CVERecord?id=CVE-2026-46127 Référence CVE CVE-2026-46128 https://www.cve.org/CVERecord?id=CVE-2026-46128 Référence CVE CVE-2026-46129 https://www.cve.org/CVERecord?id=CVE-2026-46129 Référence CVE CVE-2026-46130 https://www.cve.org/CVERecord?id=CVE-2026-46130 Référence CVE CVE-2026-46131 https://www.cve.org/CVERecord?id=CVE-2026-46131 Référence CVE CVE-2026-46132 https://www.cve.org/CVERecord?id=

Official advisory
CERT-FR · French · CERTFR-2026-AVI-0926Multiples vulnérabilités dans le noyau Linux d'Ubuntu

d?id=CVE-2026-46115 Référence CVE CVE-2026-46116 https://www.cve.org/CVERecord?id=CVE-2026-46116 Référence CVE CVE-2026-46117 https://www.cve.org/CVERecord?id=CVE-2026-46117 Référence CVE CVE-2026-46118 https://www.cve.org/CVERecord?id=CVE-2026-46118 Référence CVE CVE-2026-46119 https://www.cve.org/CVERecord?id=CVE-2026-46119 Référence CVE CVE-2026-46120 https://www.cve.org/CVERecord?id=CVE-2026-46120 Référence CVE CVE-2026-46121 https://www.cve.org/CVERecord?id=CVE-2026-46121 Référence CVE CVE-2026-46122 https://www.cve.org/CVERecord?id=CVE-2026-46122 Référence CVE CVE-2026-46123 https://www.cve.org/CVERecord?id=CVE-2026-46123 Référence CVE CVE-2026-46124 https://www.cve.org/CVERecord?id=CVE-2026-46124 Référence CVE CVE-2026-46125 https://www.cve.org/CVERecord?id=CVE-2026-46125 Référence CVE CVE-2026-46126 https://www.cve.org/CVERecord?id=CVE-2026-46126 Référence CVE CVE-2026-46127 https://www.cve.org/CVERecord?id=CVE-2026-46127 Référence CVE CVE-2026-46128 https://www.cve.org/CVERecord?id=CVE-2026-46128 Référence CVE CVE-2026-46129 https://www.cve.org/CVERecord?id=CVE-2026-46129 Référence CVE CVE-2026-46130 https://www.cve.org/CVERecord?id=CVE-2026-46130 Référence CVE CVE-2026-46131 https://www.cve.org/CVERecord?id=CVE-2026-46131 Référence CVE CVE-2026-46132 https://www.cve.org/CVERecord?id=

Official advisory
CERT-FR · French · CERTFR-2026-AVI-0927Multiples vulnérabilités dans le noyau Linux de SUSE

d?id=CVE-2026-46102 Référence CVE CVE-2026-46103 https://www.cve.org/CVERecord?id=CVE-2026-46103 Référence CVE CVE-2026-46108 https://www.cve.org/CVERecord?id=CVE-2026-46108 Référence CVE CVE-2026-46111 https://www.cve.org/CVERecord?id=CVE-2026-46111 Référence CVE CVE-2026-46112 https://www.cve.org/CVERecord?id=CVE-2026-46112 Référence CVE CVE-2026-46116 https://www.cve.org/CVERecord?id=CVE-2026-46116 Référence CVE CVE-2026-46119 https://www.cve.org/CVERecord?id=CVE-2026-46119 Référence CVE CVE-2026-46120 https://www.cve.org/CVERecord?id=CVE-2026-46120 Référence CVE CVE-2026-46122 https://www.cve.org/CVERecord?id=CVE-2026-46122 Référence CVE CVE-2026-46124 https://www.cve.org/CVERecord?id=CVE-2026-46124 Référence CVE CVE-2026-46125 https://www.cve.org/CVERecord?id=CVE-2026-46125 Référence CVE CVE-2026-46128 https://www.cve.org/CVERecord?id=CVE-2026-46128 Référence CVE CVE-2026-46131 https://www.cve.org/CVERecord?id=CVE-2026-46131 Référence CVE CVE-2026-46132 https://www.cve.org/CVERecord?id=CVE-2026-46132 Référence CVE CVE-2026-46136 https://www.cve.org/CVERecord?id=CVE-2026-46136 Référence CVE CVE-2026-46138 https://www.cve.org/CVERecord?id=CVE-2026-46138 Référence CVE CVE-2026-46140 https://www.cve.org/CVERecord?id=CVE-2026-46140 Référence CVE CVE-2026-46143 https://www.cve.org/CVERecord?id=

Official advisory
CERT-FR · French · CERTFR-2026-AVI-0900Multiples vulnérabilités dans le noyau Linux de SUSE

d?id=CVE-2026-45960 Référence CVE CVE-2026-45970 https://www.cve.org/CVERecord?id=CVE-2026-45970 Référence CVE CVE-2026-46028 https://www.cve.org/CVERecord?id=CVE-2026-46028 Référence CVE CVE-2026-46065 https://www.cve.org/CVERecord?id=CVE-2026-46065 Référence CVE CVE-2026-46069 https://www.cve.org/CVERecord?id=CVE-2026-46069 Référence CVE CVE-2026-46082 https://www.cve.org/CVERecord?id=CVE-2026-46082 Référence CVE CVE-2026-46090 https://www.cve.org/CVERecord?id=CVE-2026-46090 Référence CVE CVE-2026-46113 https://www.cve.org/CVERecord?id=CVE-2026-46113 Référence CVE CVE-2026-46120 https://www.cve.org/CVERecord?id=CVE-2026-46120 Référence CVE CVE-2026-46124 https://www.cve.org/CVERecord?id=CVE-2026-46124 Référence CVE CVE-2026-46133 https://www.cve.org/CVERecord?id=CVE-2026-46133 Référence CVE CVE-2026-46173 https://www.cve.org/CVERecord?id=CVE-2026-46173 Référence CVE CVE-2026-46197 https://www.cve.org/CVERecord?id=CVE-2026-46197 Référence CVE CVE-2026-46227 https://www.cve.org/CVERecord?id=CVE-2026-46227 Référence CVE CVE-2026-46229 https://www.cve.org/CVERecord?id=CVE-2026-46229 Référence CVE CVE-2026-46243 https://www.cve.org/CVERecord?id=CVE-2026-46243 Référence CVE CVE-2026-46253 https://www.cve.org/CVERecord?id=CVE-2026-46253 Référence CVE CVE-2026-46254 https://www.cve.org/CVERecord?id=

Official advisory
CERT-FR · French · CERTFR-2026-AVI-0864Multiples vulnérabilités dans le noyau Linux de SUSE

d?id=CVE-2026-46110 Référence CVE CVE-2026-46111 https://www.cve.org/CVERecord?id=CVE-2026-46111 Référence CVE CVE-2026-46112 https://www.cve.org/CVERecord?id=CVE-2026-46112 Référence CVE CVE-2026-46113 https://www.cve.org/CVERecord?id=CVE-2026-46113 Référence CVE CVE-2026-46114 https://www.cve.org/CVERecord?id=CVE-2026-46114 Référence CVE CVE-2026-46116 https://www.cve.org/CVERecord?id=CVE-2026-46116 Référence CVE CVE-2026-46119 https://www.cve.org/CVERecord?id=CVE-2026-46119 Référence CVE CVE-2026-46120 https://www.cve.org/CVERecord?id=CVE-2026-46120 Référence CVE CVE-2026-46123 https://www.cve.org/CVERecord?id=CVE-2026-46123 Référence CVE CVE-2026-46124 https://www.cve.org/CVERecord?id=CVE-2026-46124 Référence CVE CVE-2026-46133 https://www.cve.org/CVERecord?id=CVE-2026-46133 Référence CVE CVE-2026-46150 https://www.cve.org/CVERecord?id=CVE-2026-46150 Référence CVE CVE-2026-46157 https://www.cve.org/CVERecord?id=CVE-2026-46157 Référence CVE CVE-2026-46159 https://www.cve.org/CVERecord?id=CVE-2026-46159 Référence CVE CVE-2026-46160 https://www.cve.org/CVERecord?id=CVE-2026-46160 Référence CVE CVE-2026-46162 https://www.cve.org/CVERecord?id=CVE-2026-46162 Référence CVE CVE-2026-46172 https://www.cve.org/CVERecord?id=CVE-2026-46172 Référence CVE CVE-2026-46173 https://www.cve.org/CVERecord?id=

Official advisory
CERT-FR · French · CERTFR-2026-AVI-0862Multiples vulnérabilités dans le noyau Linux de Debian LTS

d?id=CVE-2026-46109 Référence CVE CVE-2026-46110 https://www.cve.org/CVERecord?id=CVE-2026-46110 Référence CVE CVE-2026-46112 https://www.cve.org/CVERecord?id=CVE-2026-46112 Référence CVE CVE-2026-46113 https://www.cve.org/CVERecord?id=CVE-2026-46113 Référence CVE CVE-2026-46116 https://www.cve.org/CVERecord?id=CVE-2026-46116 Référence CVE CVE-2026-46119 https://www.cve.org/CVERecord?id=CVE-2026-46119 Référence CVE CVE-2026-46120 https://www.cve.org/CVERecord?id=CVE-2026-46120 Référence CVE CVE-2026-46122 https://www.cve.org/CVERecord?id=CVE-2026-46122 Référence CVE CVE-2026-46123 https://www.cve.org/CVERecord?id=CVE-2026-46123 Référence CVE CVE-2026-46124 https://www.cve.org/CVERecord?id=CVE-2026-46124 Référence CVE CVE-2026-46125 https://www.cve.org/CVERecord?id=CVE-2026-46125 Référence CVE CVE-2026-46127 https://www.cve.org/CVERecord?id=CVE-2026-46127 Référence CVE CVE-2026-46128 https://www.cve.org/CVERecord?id=CVE-2026-46128 Référence CVE CVE-2026-46129 https://www.cve.org/CVERecord?id=CVE-2026-46129 Référence CVE CVE-2026-46132 https://www.cve.org/CVERecord?id=CVE-2026-46132 Référence CVE CVE-2026-46133 https://www.cve.org/CVERecord?id=CVE-2026-46133 Référence CVE CVE-2026-46136 https://www.cve.org/CVERecord?id=CVE-2026-46136 Référence CVE CVE-2026-46137 https://www.cve.org/CVERecord?id=

Official advisory
CERT-FR · French · CERTFR-2026-AVI-0731Multiples vulnérabilités dans les produits Microsoft

mai 2026 Bulletin de sécurité Microsoft CVE-2026-46111 du 29 mai 2026 Bulletin de sécurité Microsoft CVE-2026-46112 du 29 mai 2026 Bulletin de sécurité Microsoft CVE-2026-46113 du 29 mai 2026 Bulletin de sécurité Microsoft CVE-2026-46114 du 29 mai 2026 Bulletin de sécurité Microsoft CVE-2026-46115 du 29 mai 2026 Bulletin de sécurité Microsoft CVE-2026-46116 du 29 mai 2026 Bulletin de sécurité Microsoft CVE-2026-46119 du 29 mai 2026 Bulletin de sécurité Microsoft CVE-2026-46120 du 29 mai 2026 Bulletin de sécurité Microsoft CVE-2026-46122 du 29 mai 2026 Bulletin de sécurité Microsoft CVE-2026-46123 du 29 mai 2026 Bulletin de sécurité Microsoft CVE-2026-46124 du 29 mai 2026 Bulletin de sécurité Microsoft CVE-2026-46125 du 29 mai 2026 Bulletin de sécurité Microsoft CVE-2026-46127 du 29 mai 2026 Bulletin de sécurité Microsoft CVE-2026-46128 du 29 mai 2026 Bulletin de sécurité Microsoft CVE-2026-46129 du 29 mai 2026 Bulletin de sécurité Microsoft CVE-2026-46131 du 29 mai 2026 Bulletin de sécurité Microsoft CVE-2026-46132 du 29 mai 2026 Bulletin de sécurité Microsoft CVE-2026-46133 du 29 mai 2026 Bulletin de sécurité Microsoft CVE-2026-46136 du 29 mai 2026 Bulletin de sécurité Microsoft CVE-2026-46137 du 29 mai 2026 Bulletin de sécurité Microsoft CVE-2026-46138 du 29 mai 2026 Bulletin de sécurité Mic

Official advisory
03

Patch and workaround

Operational remediation based on structured source evidence.

Status
?Patch availability is based on structured fixed-version fields and authoritative update references. If no fix is verified, check the vendor advisory before making a change.
Patch available
Affected
5e7de55602c61c8ff28db075cc49c8dd6989d7e0 < ee0024f5a7e3c73aa253869fae9650ae054093ca; 63d5a3e207bf315a32c7d16de6c89753a759f95a < 31dbb4ba0f719ae7774e4c0c95172c9bf81692f5; 0fdafdaef796816a9ed0fd7ac812932d569d9beb < 908a76f0b1038035e6ebb4f2293ce079f92e0a02; 952e7a7e317f126d0a2b879fc531b716932d5ffa < bb0988ed4f2e26d59bbb58f644cb3a55b7521e21; 56dfffea9fd3be0b3795a9ca6401e133a8427e0b < 0a1af74ae2177bda3aee0837a0546309aa539d0d; 0405d4b63d082861f4eaff9d39c78ee9dc34f845 < afbafeddf23db13fe2edb2d5c0bf4bbb13d7881b; 0405d4b63d082861f4eaff9d39c78ee9dc34f845 < 4c721a1d9b3c4fcaf59cc9b2281e3ec5a043e1a6; 0405d4b63d082861f4eaff9d39c78ee9dc34f845 < 24376458138387fb251e782e624c7776e9826796
Fixed
< 6.15; 5.10.258 ≤ 5.10.*; 5.15.209 ≤ 5.15.*; 6.1.175 ≤ 6.1.*; 6.6.140 ≤ 6.6.*; 6.12.88 ≤ 6.12.*; 6.18.30 ≤ 6.18.*; 7.0.7 ≤ 7.0.*
Action
Review the linked authoritative reference and apply the recorded fixed release appropriate to the affected product branch.
Workaround
No verified workaround is recorded. If business-safe, reduce exposure to the affected interface and allow only trusted sources until authoritative guidance is available.
04

Evidence and provenance

Published 28 May 2026 · Last source change 5 Aug 2026, 12:29 UTC · CWE not yet assigned

CVE recordCVE.org · 5.2
CVSS sourceCNA
EPSS source
?The date BlackTree first stored a score for this CVE from the daily FIRST EPSS feed.
FIRST · tracked since 2026-08-14
European sourceENISA EUVD · EUVD-2026-32883
Product sourceCNA
Remediation sourceCVE/CNA references
CWE sourceUnavailable
NVD statusNVD enrichment underway

Missing structured fields: CWE classification. Missing data is not evidence of low risk; review the primary advisory.

Material change intelligence

What changed after publication

View recent updates →

No material field changes have been recorded since change tracking began. Routine source refreshes and cosmetic edits are intentionally excluded.

Material fields only · duplicate refreshes suppressed · history retained for the configured operational retention period
Technical terms and abbreviations used in this report
CVE
Common Vulnerabilities and Exposures: the public identifier for one disclosed vulnerability.
CVSS
Common Vulnerability Scoring System: a technical severity framework; it is not patching priority by itself.
EPSS
Exploit Prediction Scoring System: FIRST's estimate of the probability that exploitation activity will be observed in the next 30 days; it is a forecast, not confirmation.
CWE
Common Weakness Enumeration: the standard category describing the underlying software or hardware weakness.
CNA
CVE Numbering Authority: an organisation authorised to assign and publish CVE records.
CISA ADP
Cybersecurity and Infrastructure Security Agency Authorized Data Publisher: structured enrichment added to a CVE record.
NVD
National Vulnerability Database: NIST's enrichment service for CVE records.
CERT / CSIRT
A computer security incident response team that publishes warnings or coordinates incident response.
PoC
Proof of concept: public material that demonstrates or helps reproduce exploitation.
CSAF
Common Security Advisory Framework: a machine-readable format for security advisories.
LoTL
Living off the land: abuse of legitimate tools or system functions during an attack.
Free version - for non-commercial use only.CVE-2026-46124 · cve.blacktree.nl