CVE-2026-46094: ext4: fix bounds check in check_xattrs() to prevent out-of-bounds access
Published May 27, 2026
·Updated
ext4: fix bounds check in checkxattrs() to prevent out-of-bounds access
Affected Software
6 affected componentsFixes available
Linux Linux kernel (ext4)
Linux Linux kernel>=6.3<6.6.140
Linux Linux kernel>=6.7<6.12.86
Linux Linux kernel>=6.13<6.18.27
Linux Linux kernel>=6.19<7.0.4
Microsoft azl3 kernel 6.6.139.1-1<6.6.141.1-1
6.6.141.1-1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.6.141.1-1
Event History
May 27, 2026
CVE Published
via MITRE·12:58 PM
Data Sourced
via MITRE·12:58 PM
Description
Data Sourced
via NVD·02:17 PM
RemedyDescriptionSeverityWeaknessAffected Software
May 28, 2026
Data Sourced
via Microsoft·08:13 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·08:13 AM
Affected Software
Updated
via Microsoft·08:13 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2026-46094?
CVE-2026-46094 has been classified with a risk score of 37.
2
How do I fix CVE-2026-46094?
To fix CVE-2026-46094, ensure you update to the latest version of the Linux kernel that includes the patch for this vulnerability.
3
What systems are affected by CVE-2026-46094?
CVE-2026-46094 affects the ext4 filesystem within the Linux kernel.
4
What are the potential consequences of CVE-2026-46094?
CVE-2026-46094 can lead to out-of-bounds access, which may result in data corruption or system crashes.
5
When was CVE-2026-46094 published?
CVE-2026-46094 was published on May 27, 2026.