8.2
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
Description
In the Linux kernel, the following vulnerability has been resolved:
ipv4: icmp: validate reply type before using icmp_pointers
Extended echo replies use ICMP_EXT_ECHOREPLY as the outbound reply type.
That value is outside the range covered by icmp_pointers[], which only
describes the traditional ICMP types up to NR_ICMP_TYPES.
Avoid consulting icmp_pointers[] for reply types outside that range, and
use array_index_nospec() for the remaining in-range lookup. Normal ICMP
replies keep their existing behavior unchanged.
ipv4: icmp: validate reply type before using icmp_pointers
Extended echo replies use ICMP_EXT_ECHOREPLY as the outbound reply type.
That value is outside the range covered by icmp_pointers[], which only
describes the traditional ICMP types up to NR_ICMP_TYPES.
Avoid consulting icmp_pointers[] for reply types outside that range, and
use array_index_nospec() for the remaining in-range lookup. Normal ICMP
replies keep their existing behavior unchanged.
Basic Information
ID
CVE-2026-46037
Source
Linux
Published
May 27, 2026 at 12:56
Modified
May 30, 2026 at 10:46
Affected Product
Vendor
Linux
Product
Linux
Version
d329ea5bd8845f0b196bf41b18b6173340d6e0e4
Affected Versions
Linux Linux d329ea5bd8845f0b196bf41b18b6173340d6e0e4
Linux Linux d329ea5bd8845f0b196bf41b18b6173340d6e0e4
Linux Linux d329ea5bd8845f0b196bf41b18b6173340d6e0e4
Linux Linux d329ea5bd8845f0b196bf41b18b6173340d6e0e4
Linux Linux d329ea5bd8845f0b196bf41b18b6173340d6e0e4
Linux Linux 5.13
Linux Linux d329ea5bd8845f0b196bf41b18b6173340d6e0e4
Linux Linux d329ea5bd8845f0b196bf41b18b6173340d6e0e4
Linux Linux d329ea5bd8845f0b196bf41b18b6173340d6e0e4
Linux Linux d329ea5bd8845f0b196bf41b18b6173340d6e0e4
Linux Linux 5.13
References
- git.kernel.org /stable/c/92e7c209036dcc0e8ffdf806fdfd3645b263bea5
- git.kernel.org /stable/c/bc64a66e0b9ad937d3d49934242ee62b01ba9a94
- git.kernel.org /stable/c/c2178ff1c70ebfc2ab9651b230c58a34683db759
- git.kernel.org /stable/c/d700c34a5d186b9ba0715bcb19e0ff80ffbfbfc1
- git.kernel.org /stable/c/67bf002a2d7387a6312138210d0bd06e3cf4879b