cbcvebase.
CVE-2026-46027
published 2026-05-27

CVE-2026-46027: In the Linux kernel, the following vulnerability has been resolved: net/smc: avoid early lgr access in smc_clc_wait_msg A CLC decline can be received while the…

PriorityP342high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.50%
40.1th percentile
In the Linux kernel, the following vulnerability has been resolved: net/smc: avoid early lgr access in smc_clc_wait_msg A CLC decline can be received while the handshake is still in an early stage, before the connection has been associated with a link group. The decline handling in smc_clc_wait_msg() updates link-group level sync state for first-contact declines, but that state only exists after link group setup has completed. Guard the link-group update accordingly and keep the per-socket peer diagnosis handling unchanged. This preserves the existing sync_err handling for established link-group contexts and avoids touching link-group state before it is available.

Affected

57 ranges· showing 25
VendorProductVersion rangeFixed in
linuxlinux
linuxlinux>= 0cfdd8f92cac01afbb12e4500514036a2b78756b < 257cdf0c5ced9c0fba8aba501d94b0a5fcef2086257cdf0c5ced9c0fba8aba501d94b0a5fcef2086
linuxlinux>= 0cfdd8f92cac01afbb12e4500514036a2b78756b < 22546729b96fc873b23065dc49e3d73c45cfb87422546729b96fc873b23065dc49e3d73c45cfb874
linuxlinux>= 0cfdd8f92cac01afbb12e4500514036a2b78756b < 5eedbfd82c2884e0010fdfb3c9446a6ebcadb6915eedbfd82c2884e0010fdfb3c9446a6ebcadb691
linuxlinux>= 0cfdd8f92cac01afbb12e4500514036a2b78756b < f0858e1d5624bb120b198f2a8528f97a9b0ae069f0858e1d5624bb120b198f2a8528f97a9b0ae069
linuxlinux>= 0cfdd8f92cac01afbb12e4500514036a2b78756b < 6180a296ca65b08a81914805cbc0f78da5f10a1f6180a296ca65b08a81914805cbc0f78da5f10a1f
linuxlinux>= 0cfdd8f92cac01afbb12e4500514036a2b78756b < ea0b5d0fe96356dce38f98375a57c52a04e13712ea0b5d0fe96356dce38f98375a57c52a04e13712
linuxlinux>= 0cfdd8f92cac01afbb12e4500514036a2b78756b < 83bcf9228b0501694fb2589ed1d142855a2887f283bcf9228b0501694fb2589ed1d142855a2887f2
linuxlinux>= 0cfdd8f92cac01afbb12e4500514036a2b78756b < 5a8db80f721deee8e916c2cfdee78decda02ce4f5a8db80f721deee8e916c2cfdee78decda02ce4f
linuxlinux_kernel
linuxlinux_kernel>= 4.11 < 5.10.2585.10.258
linuxlinux_kernel>= 5.11 < 5.15.2095.15.209
linuxlinux_kernel>= 5.16 < 6.1.1756.1.175
linuxlinux_kernel>= 6.13 < 6.18.276.18.27
linuxlinux_kernel>= 6.19 < 7.0.47.0.4
linuxlinux_kernel>= 6.2 < 6.6.1406.6.140
linuxlinux_kernel>= 6.7 < 6.12.866.12.86
ubuntulinux
ubuntulinux-aws
ubuntulinux-aws-5.15
ubuntulinux-aws-fips
ubuntulinux-azure
ubuntulinux-azure-5.15
ubuntulinux-azure-6.8
ubuntulinux-azure-fde

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
vendor_ubuntu8.8HIGH
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.