CVE-2026-46152 Affecting kernel-tools-libs-devel package, versions <0:4.18.0-553.134.1.el8_10


Severity

Recommended
high

Based on Rocky Linux security rating.

Threat Intelligence

EPSS
0.28% (20th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-ROCKY8-KERNELTOOLSLIBSDEVEL-17389659
  • published20 Jun 2026
  • disclosed28 May 2026

Introduced: 28 May 2026

NewCVE-2026-46152  (opens in a new tab)

How to fix?

Upgrade Rocky-Linux:8 kernel-tools-libs-devel to version 0:4.18.0-553.134.1.el8_10 or higher.
This issue was patched in RLSA-2026:26427.

NVD Description

Note: Versions mentioned in the description apply only to the upstream kernel-tools-libs-devel package and not the kernel-tools-libs-devel package as distributed by Rocky-Linux. See How to fix? for Rocky-Linux:8 relevant fixed versions and status.

In the Linux kernel, the following vulnerability has been resolved:

wifi: mac80211: drop stray 'static' from fast-RX rx_result

ieee80211_invoke_fast_rx() is documented as safe for parallel RX, but its per-invocation rx_result is declared static. Concurrent callers then share one instance and can overwrite each other's result between ieee80211_rx_mesh_data() and the switch on res.

That can make a packet that was queued or consumed by ieee80211_rx_mesh_data() fall through into ieee80211_rx_8023(), or make a packet that should continue return as queued.

Make res an automatic variable so each invocation keeps its own result.

CVSS Base Scores

version 3.1