Junglewise Threat Intelligence

CVE-2026-46026: Linux Kernel resource exhaustion in QRTR nameservice

CVE-2026-46026 · Severity: info · CVSS 3.3 · Published 2026-05-27

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's networking component responsible for Qualcomm IPC Router (QRTR) services. A local user could potentially overwhelm the system by sending a flood of service lookup requests, leading to excessive resource consumption. This issue has been resolved by implementing a limit on the maximum number of concurrent lookups allowed.

Technical details

A vulnerability in the QRTR (Qualcomm IPC Router) nameservice (ns.c) in the Linux kernel allowed local clients to perform an unlimited number of service lookups. By sending a flood of NEW_LOOKUP messages over a single socket, a malicious local actor could cause excessive memory allocation or processing overhead. The fix introduces a global limit (QRTR_NS_MAX_LOOKUPS) set to 64 to ensure the nameserver remains stable. This is primarily a local denial-of-service (DoS) vector.

Affected products

  • Linux Linux Kernel Fixed in versions 0dbec10, 20855ce, 2b930bc, 5640227, 76adf8f

Timeline

  • 2026-04-09: other: Initial patch submitted by developer
  • 2026-05-27: advisory: CVE-2026-46026 published

References