Affects core Linux kernel networking on IBM Power systems; potential widespread disruption across industries; widely-used infrastructure.
CVE-2026-46273
Linux kernel ibmveth: disable GSO for MSS < 224 to avoid NIC freeze.
Is CVE-2026-46273 being exploited?
Not confirmed. CVE-2026-46273 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.39% probability of exploitation in the next 30 days.
How severe is CVE-2026-46273?
CVE-2026-46273 is rated High with a CVSS score of 8.6. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-46273?
Yes. A fix has been recorded for CVE-2026-46273. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-46273 affect?
CVE-2026-46273 affects Linux kernel (ibmveth) driver on IBM Power Systems with SEA configurations. Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-46273?
Apply patched kernel; verify GSO handling for small MSS; monitor NIC stability.
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Remote DoS: small MSS GSO packets may freeze NIC, halting traffic until reset.
Patch when possible
- affected>= 8641dd85799f85bef5f0d1f87356aaa12cb2195e and < 86fc64584811d43c9ccd74447de58620189d8b77
- affected>= 8641dd85799f85bef5f0d1f87356aaa12cb2195e and < 9a5e984d7af910e46dcbed3ce77873e000a4f77d
- affected>= 8641dd85799f85bef5f0d1f87356aaa12cb2195e and < 1cdf5dbcec988d06f5f720bdf89e91073f77fa10
- affected>= 8641dd85799f85bef5f0d1f87356aaa12cb2195e and < 82bc89fbb82d9396fb4eaee8720ea85e2e787957
- affected>= 8641dd85799f85bef5f0d1f87356aaa12cb2195e and < db8012c631cb845e9ae2b4b531e17d86c9519755
- affected>= 8641dd85799f85bef5f0d1f87356aaa12cb2195e and < c1f261863e65b508f37416dfbc5c5d911c9b9233
- affected>= 8641dd85799f85bef5f0d1f87356aaa12cb2195e and < 3af24f0c4c31f18a4a2d927990759194832bb6e9
- affected>= 8641dd85799f85bef5f0d1f87356aaa12cb2195e and < cc427d24ac6442ffdeafd157a63c7c5b73ed4de4
- affected4.2
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.