Executive brief
A vulnerability was identified in the Linux kernel's networking component responsible for Qualcomm IPC Router (QRTR) services. A local user could potentially overwhelm the system by sending a flood of service lookup requests, leading to excessive resource consumption. This issue has been resolved by implementing a limit on the maximum number of concurrent lookups allowed.
Technical details
A vulnerability in the QRTR (Qualcomm IPC Router) nameservice (ns.c) in the Linux kernel allowed local clients to perform an unlimited number of service lookups. By sending a flood of NEW_LOOKUP messages over a single socket, a malicious local actor could cause excessive memory allocation or processing overhead. The fix introduces a global limit (QRTR_NS_MAX_LOOKUPS) set to 64 to ensure the nameserver remains stable. This is primarily a local denial-of-service (DoS) vector.
Affected products
- Linux Linux Kernel Fixed in versions 0dbec10, 20855ce, 2b930bc, 5640227, 76adf8f
Timeline
- 2026-04-09: other: Initial patch submitted by developer
- 2026-05-27: advisory: CVE-2026-46026 published
References
- https://git.kernel.org/stable/c/0dbec101a7076e9b1e4bd1876f7cf07c56ff4ce3
- https://git.kernel.org/stable/c/20855cef7e659ef84ac73251256fa530819b2346
- https://git.kernel.org/stable/c/2b930bc77e00cb27e1d6e1d497b3b596283465ef
- https://git.kernel.org/stable/c/5640227d9a21c6a8be249a10677b832e7f40dc55
- https://git.kernel.org/stable/c/76adf8f69b0bb3ab20be7c58f5d555027332d113