CVE-2026-46123
Maxim Suhanov discovered that the NTFS file system implementation in the Linux kernel did not properly validate file name length in certain situations, leading to an out-of-bounds read. An attacker could use this to construct a malicious NTFS image that, when mounted and operated on, could expose sensitive information (kernel memory). (CVE-2023-45896) It was discovered that some AMD processors did not properly clear data in the floating point divider unit during speculative execution. A local attacker could use this to expose sensitive information. (CVE-2025-54505) It was discovered that some AMD Zen 2 processors did not properly isolate shared resources in the operation cache. A local attacker could possibly use this issue to corrupt instructions executed at a higher privilege level, resulting in privilege escalation. (CVE-2025-54518) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM32 architecture; - ARM64 architecture; - MIPS architecture; - PowerPC architecture; - S390 architecture; - x86 architecture; - Block layer subsystem; - Cryptographic API; - ACPI drivers; - ATM drivers; - Drivers core; - Power management core; - DRBD Distributed Replicated Block Device drivers; - RNBD block device driver; - Bluetooth drivers; - Bus devices; - Character device driver; - TPM device driver; - Clocksource drivers; - Data acquisition framework and drivers; - CPU frequency scaling framework; - CPU idle management framework; - Hardware crypto device drivers; - DMA engine subsystem; - Arm Firmware Framework for ARMv8-A(FFA); - EFI core; - GPIO subsystem; - GPU drivers; - HID subsystem; - Hardware monitoring drivers; - I2C subsystem; - IIO subsystem; - IIO ADC drivers; - InfiniBand drivers; - Input Device (Miscellaneous) drivers; - IOMMU subsystem; - Mailbox framework; - Multiple devices driver; - Media drivers; - MediaTek SMI driver; - NVIDIA Te
CSIRTS triage
- What
- Multiple vulnerabilities in the Linux kernel can lead to information exposure and privilege escalation.
- Who is affected
- Systems running affected versions of the Linux kernel, particularly those using AMD processors.
- Urgency
- Remediation is high priority due to the severity of the vulnerabilities and potential for exploitation.
- Action
- Apply the latest security updates for the Linux kernel.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2026-46123
Get an email if CVE-2026-46123 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Low exploitation risk0.14% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 4% of all EPSS-scored CVEs.
Advisory coverage (30)
- highUSN-8620-4: Linux kernel (Intel IoTG) vulnerabilitiesubuntu · 2026-07-31
- highUSN-8620-3: Linux kernel (Intel IoTG) vulnerabilitiesubuntu · 2026-07-31
- highUSN-8620-2: Linux kernel (Azure FIPS) vulnerabilitiesubuntu · 2026-07-29
- highUSN-8620-1: Linux kernel vulnerabilitiesubuntu · 2026-07-28
- highUSN-8619-1: Linux kernel (HWE) vulnerabilitiesubuntu · 2026-07-28
- highUSN-8595-3: Linux kernel (AWS) vulnerabilitiesubuntu · 2026-07-28
- highUSN-8574-3: Linux kernel vulnerabilitiesubuntu · 2026-07-28
- highUSN-8618-1: Linux kernel vulnerabilitiesubuntu · 2026-07-28
- highUSN-8610-1: Linux kernel (Azure CVM) vulnerabilitiesubuntu · 2026-07-24
- highUSN-8575-3: Linux kernel vulnerabilitiesubuntu · 2026-07-24
- highUSN-8609-1: Linux kernel (Azure CVM) vulnerabilitiesubuntu · 2026-07-24
- highUSN-8608-1: Linux kernel (Azure FIPS) vulnerabilitiesubuntu · 2026-07-24
- highUSN-8607-1: Linux kernel (Azure CVM) vulnerabilitiesubuntu · 2026-07-24
- highUSN-8606-1: Linux kernel (Azure) vulnerabilitiesubuntu · 2026-07-24
- highUSN-8595-2: Linux kernel (AWS) vulnerabilitiesubuntu · 2026-07-24
- highUSN-8603-1: Linux kernel (Azure) vulnerabilitiesubuntu · 2026-07-24
- highUSN-8597-1: Linux kernel (IBM) vulnerabilitiesubuntu · 2026-07-23
- highUSN-8576-2: Linux kernel (NVIDIA Tegra) vulnerabilitiesubuntu · 2026-07-23
- highUSN-8575-2: Linux kernel vulnerabilitiesubuntu · 2026-07-23
- highUSN-8596-1: Linux kernel (NVIDIA) vulnerabilitiesubuntu · 2026-07-23
- highUSN-8595-1: Linux kernel (Oracle) vulnerabilitiesubuntu · 2026-07-23
- highUSN-8574-2: Linux kernel vulnerabilitiesubuntu · 2026-07-23
- highUSN-8593-1: Linux kernel vulnerabilitiesubuntu · 2026-07-23
- highUSN-8576-1: Linux kernel (NVIDIA Tegra) vulnerabilitiesubuntu · 2026-07-21
- highUSN-8575-1: Linux kernel vulnerabilitiesubuntu · 2026-07-21
- highUSN-8574-1: Linux kernel (GCP FIPS) vulnerabilitiesubuntu · 2026-07-21
- highUSN-8569-1: Linux kernel (HWE) vulnerabilitiesubuntu · 2026-07-20
- highUSN-8568-1: Linux kernel (OEM) vulnerabilitiesubuntu · 2026-07-20
- highUSN-8567-1: Linux kernel vulnerabilitiesubuntu · 2026-07-20
- highUSN-8566-1: Linux kernel vulnerabilitiesubuntu · 2026-07-20
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-46123)