CVE-2026-46038

Source
https://cve.org/CVERecord?id=CVE-2026-46038
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-46038.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-46038
Downstream
Related
Published
2026-05-27T12:56:50.125Z
Modified
2026-06-23T03:54:57.104363733Z
Summary
net: qrtr: ns: Free the node during ctrl_cmd_bye()
Details

In the Linux kernel, the following vulnerability has been resolved:

net: qrtr: ns: Free the node during ctrlcmdbye()

A node sends the BYE packet when it is about to go down. So the nameserver should advertise the removal of the node to all remote and local observers and free the node finally. But currently, the nameserver doesn't free the node memory even after processing the BYE packet. This causes the node memory to leak.

Hence, remove the node from Xarray list and free the node memory during both success and failure case of ctrlcmdbye().

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/46xxx/CVE-2026-46038.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
0c2204a4ad710d95d348ea006f14ba926e842ffd
Fixed
6c9cca46acb6f22e63f015ea7b2ed6032d2badf5
Fixed
a5a454f3364877b22f0e5a165df8b3702ff96ae7
Fixed
25d580a46b079a7963ff024a5195e547baf12b64
Fixed
ff78ed177a66763085e3214d6fbe13ca8f0b3f11
Fixed
65932f5102bb5377db36c8a4f0c28179a1967a9a
Fixed
154fc7fe3f62c46891c3c4302f4b5b5391c932e6
Fixed
076e4b162d6caba12c229e7f262df5b6881162b0
Fixed
68efba36446a7774ea5b971257ade049272a07ac

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-46038.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.7.0
Fixed
5.10.259
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.210
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.176
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.140
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.86
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.27
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.0.4

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-46038.json"