Medium severity5.5NVD Advisory· Published May 27, 2026· Updated Jun 19, 2026
CVE-2026-46038
CVE-2026-46038
Description
In the Linux kernel, the following vulnerability has been resolved:
net: qrtr: ns: Free the node during ctrl_cmd_bye()
A node sends the BYE packet when it is about to go down. So the nameserver should advertise the removal of the node to all remote and local observers and free the node finally. But currently, the nameserver doesn't free the node memory even after processing the BYE packet. This causes the node memory to leak.
Hence, remove the node from Xarray list and free the node memory during both success and failure case of ctrl_cmd_bye().
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
18- osv-coords15 versionspkg:linux/kernelpkg:rpm/opensuse/dtb-aarch64&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/kernel-64kb&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/kernel-azure&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/kernel-default&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/kernel-default-base&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/kernel-docs&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/kernel-kvmsmall&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/kernel-obs-build&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/kernel-obs-qa&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/kernel-rt&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/kernel-source&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/kernel-source&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/kernel-syms&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/kernel-zfcpdump&distro=openSUSE%20Leap%2016.0
>= 5.7.0, < 5.10.259+ 14 more
- (no CPE)range: >= 5.7.0, < 5.10.259
- (no CPE)range: < 6.12.0-160000.37.1
- (no CPE)range: < 6.12.0-160000.37.1
- (no CPE)range: < 6.12.0-160000.37.1
- (no CPE)range: < 6.12.0-160000.37.1
- (no CPE)range: < 6.12.0-160000.37.1.160000.2.19
- (no CPE)range: < 6.12.0-160000.37.1
- (no CPE)range: < 6.12.0-160000.37.1
- (no CPE)range: < 6.12.0-160000.37.1
- (no CPE)range: < 6.12.0-160000.37.1
- (no CPE)range: < 6.12.0-160000.37.1
- (no CPE)range: < 6.12.0-160000.37.1
- (no CPE)range: < 7.0.11-1.1
- (no CPE)range: < 6.12.0-160000.37.1
- (no CPE)range: < 6.12.0-160000.37.1
Patches
Vulnerability mechanics
References
8- git.kernel.org/stable/c/076e4b162d6caba12c229e7f262df5b6881162b0nvdPatch
- git.kernel.org/stable/c/154fc7fe3f62c46891c3c4302f4b5b5391c932e6nvdPatch
- git.kernel.org/stable/c/65932f5102bb5377db36c8a4f0c28179a1967a9anvdPatch
- git.kernel.org/stable/c/68efba36446a7774ea5b971257ade049272a07acnvdPatch
- git.kernel.org/stable/c/ff78ed177a66763085e3214d6fbe13ca8f0b3f11nvdPatch
- git.kernel.org/stable/c/25d580a46b079a7963ff024a5195e547baf12b64nvd
- git.kernel.org/stable/c/6c9cca46acb6f22e63f015ea7b2ed6032d2badf5nvd
- git.kernel.org/stable/c/a5a454f3364877b22f0e5a165df8b3702ff96ae7nvd
News mentions
0No linked articles in our index yet.