CVE-2026-46039: Linux Kernel

Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: rxgk: Fix potential integer overflow in length check Fix potential integer overflow in rxgk_extract_token() when checking the length of the ticket. Rather than rounding up the value to be tested (which might overflow), round down the size of the available data.

Affected products

  • Linux Linux Kernel: from 6.16.9, before 6.17 (fixed in 6.17); from 6.17.1, before 6.18.27 (fixed in 6.18.27); from 6.19, before 7.0.4 (fixed in 7.0.4); version 6.17 only

Published 2026-05-27. Last modified 2026-06-17.