Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2026-46064

7.1 · HIGH
Published May 27, 2026 linux CWE-125 EPSS 0.14% (4th pctl)

Overview

CVE-2026-46064 is a high-severity vulnerability affecting linux linux_kernel. It was published on May 27, 2026 and has a CVSS 3.1 base score of 7.1 (HIGH).

This vulnerability has a CVSS 3.1 base score of 7.1, rated HIGH. It requires local or adjacent network access to exploit. Some level of privileges is required for exploitation.

Technical Description

In the Linux kernel, the following vulnerability has been resolved:

ibmasm: fix heap over-read in ibmasm_send_i2o_message()

The ibmasm_send_i2o_message() function uses get_dot_command_size() to

compute the byte count for memcpy_toio(), but this value is derived from

user-controlled fields in the dot_command_header (command_size: u8,

data_size: u16) and is never validated against the actual allocation size.

A root user can write a small buffer with inflated header fields, causing

memcpy_toio() to read up to ~65 KB past the end of the allocation into

adjacent kernel heap, which is then forwarded to the service processor

over MMIO.

Silently clamping the copy size is not sufficient: if the header fields

claim a larger size than the buffer, the SP receives a dot command whose

own header is inconsistent with the I2O message length, which can cause

the SP to desynchronize. Reject such commands outright by returning

failure.

Validate command_size before calling get_mfa_inbound() to avoid l

Remediation

Check the references section for vendor advisories and patches from linux. Update linux_kernel to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Affected Products

Vendor Product Versions Status
linux linux_kernel >= 2.6.12.1, < 5.10.258 Affected

Frequently Asked Questions

What is CVE-2026-46064?

CVE-2026-46064 is a high-severity vulnerability affecting linux linux_kernel. It was published on May 27, 2026 and has a CVSS 3.1 base score of 7.1 (HIGH).

How severe is CVE-2026-46064?

This vulnerability has a CVSS 3.1 base score of 7.1, rated HIGH. It requires local or adjacent network access to exploit. Some level of privileges is required for exploitation.

How do I fix or remediate CVE-2026-46064?

Check the references section for vendor advisories and patches from linux. Update linux_kernel to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2026-46064?

CyberStrike's AI-powered security agents can automatically detect CVE-2026-46064 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.