Kernel-level flaw in Linux/libceph; widely deployed infrastructure across industries; could disrupt services or expose memory.
CVE-2026-46119
Linux kernel: slab-out-of-bounds in libceph auth path.
Is CVE-2026-46119 being exploited?
Not confirmed. CVE-2026-46119 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.53% probability of exploitation in the next 30 days.
How severe is CVE-2026-46119?
CVE-2026-46119 is rated Critical with a CVSS score of 9.1. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-46119?
Yes. A fix has been recorded for CVE-2026-46119. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-46119 affect?
CVE-2026-46119 affects Linux kernel (libceph), Ceph clients/monitors. Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-46119?
Patch kernel to fixed version immediately
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Possible kernel memory disclosure or crash via crafted CEPH_MSG_AUTH_REPLY causing OOB access.
Immediate action required
- affected>= 4e7a5dcd1bbab6560fbc8ada29a840e7a20ed7bc and < c2374b92c729d0388a538b3cde7b3e3b5e55ef39
- affected>= 4e7a5dcd1bbab6560fbc8ada29a840e7a20ed7bc and < 38fdf04c602d52c42c67fc1617211492753b7e8b
- affected>= 4e7a5dcd1bbab6560fbc8ada29a840e7a20ed7bc and < 2ae0afd98432536562fa8261538ae795446f0589
- affected>= 4e7a5dcd1bbab6560fbc8ada29a840e7a20ed7bc and < 408e85ee708b6aa03eeb0220ffa0915f4d407181
- affected>= 4e7a5dcd1bbab6560fbc8ada29a840e7a20ed7bc and < b7df9fbd4869fdfe09a3f501ffd228486521e062
- affected>= 4e7a5dcd1bbab6560fbc8ada29a840e7a20ed7bc and < 8517b6c8d2c759918ba0058cb6c7e14d59643202
- affected>= 4e7a5dcd1bbab6560fbc8ada29a840e7a20ed7bc and < 1c439de70b1c3eb3c6bffa8245c16b9fc318f114
- affected2.6.34
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.