CVE-2026-46266: inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP
Published Jun 3, 2026
·Updated
In the Linux kernel, the following vulnerability has been resolved:
Affected Software
11 affected componentsFixes available
Linux Linux kernel
Linux Linux kernel>=2.6.12.1<6.6.128
Linux Linux kernel>=6.7<6.12.75
Linux Linux kernel>=6.13<6.18.14
Linux Linux kernel>=6.19<6.19.4
Linux Linux kernel=2.6.12
Linux Linux kernel=2.6.12-rc2
Linux Linux kernel=2.6.12-rc3
Linux Linux kernel=2.6.12-rc4
Linux Linux kernel=2.6.12-rc5
debian/linux<=5.10.223-1, <=5.10.262-1, <=6.1.176-1, <=6.1.180-1
6.12.94-16.12.105-17.1.8-27.1.10-1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.12.94-1Fixed in 6.12.105-1Fixed in 7.1.8-2Fixed in 7.1.10-1
Event History
Jun 3, 2026
CVE Published
via MITRE·03:50 PM
Data Sourced
via MITRE·03:50 PM
DescriptionSeverity
Data Sourced
via NVD·06:16 PM
RemedyDescriptionSeverityAffected Software
Aug 12, 2026
Data Sourced
via Launchpad·08:39 PM
Description
Aug 26, 2026
Data Sourced
via Ubuntu·12:33 AM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·12:34 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-46266?
CVE-2026-46266 has a severity score of 9.1, classified as critical.
2
How do I fix CVE-2026-46266?
To mitigate CVE-2026-46266, ensure your Linux kernel is updated to the version that addresses this vulnerability.
3
What impact does CVE-2026-46266 have on my system?
CVE-2026-46266 allows malicious incoming ICMP packets to exploit RAW sockets, potentially affecting system integrity and availability.
4
Who reported CVE-2026-46266?
CVE-2026-46266 was reported by Yizhou Zhao.
5
Which versions of Linux are affected by CVE-2026-46266?
CVE-2026-46266 affects the vulnerable versions of the Linux kernel that allow RAW sockets using IPPROTO_RAW.