Review reviewHigh

CVE-2026-46033

Linux Linux, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6

In the Linux kernel, the following vulnerability has been resolved: crypto: authencesn - reject short ahash digests during instance creation authencesn requires either a zero authsize or an authsize of at least 4 bytes because the ESN encrypt/decrypt paths always move 4 bytes of high-order sequence number data at the end of the authenticated data. While crypto_authenc_esn_setauthsize() already rejects explicit non-zero authsizes in the range 1..3, crypto_authenc_esn_create() still copied auth->digestsize into inst->alg.maxauthsize without validating it. The AEAD core then initialized the tf...

CVSS
7.1
EPSS
0.13%
2.93% percentile
CISA KEV
Not listed
Published
2026.05.27
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability0.13%
Technical severityCVSS 7.1

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: crypto: authencesn - reject short ahash digests during instance creation authencesn requires either a zero authsize or an authsize of at least 4 bytes because the ESN encrypt/decrypt paths always move 4 bytes of high-order sequence number data at the end of the authenticated data. While crypto_authenc_esn_setauthsize() already rejects explicit non-zero authsizes in the range 1..3, crypto_authenc_esn_create() still copied auth->digestsize into inst->alg.maxauthsize without validating it. The AEAD core then initialized the tf...

Affected product and versions

Product
Linux Linux, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6
Affected versions
>= f15f05b0a5de667c821a9727c33bce9d1d9b26dd < 77f59fb2d3aa33e90ec6cbbf45dcfb20ab82b1a9, >= f15f05b0a5de667c821a9727c33bce9d1d9b26dd < 2f31cd1e64a079c845bca31d2da7b3c90a311726, >= f15f05b0a5de667c821a9727c33bce9d1d9b26dd < d4c6a6d08e70bb1083c7c405fc7faacbf19aebc0, >= f15f05b0a5de667c821a9727c33bce9d1d9b26dd < b69933e97efea238ebbfcf70c2b1be1cd03f13e3, >= f15f05b0a5de667c821a9727c33bce9d1d9b26dd < 67f1f0933cc3d78dde222842bcad2778ec7a0b88, >= f15f05b0a5de667c821a9727c33bce9d1d9b26dd < b42821c15445f93daea3e76ada682b2b7181c476, >= f15f05b0a5de667c821a9727c33bce9d1d9b26dd < 9aff81e8217e9de2929084b03b3c7f81988c112b, >= f15f05b0a5de667c821a9727c33bce9d1d9b26dd < 5db6ef9847717329f12c5ea8aba7e9f588a980c0, >= 4.11, >= 4.11 < 5.10.258, >= 5.11 < 5.15.209, >= 5.16 < 6.1.175, >= 6.2 < 6.6.140, >= 6.7 < 6.12.86, >= 6.13 < 6.18.27, >= 6.19 < 7.0.4, 7.1
Fixed versions
5.10.258, 5.15.209, 6.1.175, 6.6.140, 6.12.86, 6.18.27, 7.0.4

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux Linux, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6 and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
CWE
CWE-125, CWE-1284