CVE-2026-46177
Last modified
CVE-2026-46177 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. In the Linux kernel, the following vulnerability has been resolved: ipmi: Add limits to event and receive message requests The driver would just fetch events and receive messages until the BMC said it was done. To avoid issues with BMCs that never say they are done, add a limit of 10 fetches at a time. In addition, an si interface has an attn state it can return from the hardware which is supposed to cause a flag fetch to see if the driver needs to fetch events or message or a few other things. EPSS estimates a 0.50% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: ipmi: Add limits to event and receive message requests The driver would just fetch events and receive messages until the BMC said it was done. To avoid issues with BMCs that never say they are done, add a limit of 10 fetches at a time. In addition, an si interface has an attn state it can return from the hardware which is supposed to cause a flag fetch to see if the driver needs to fetch events or message or a few other things. If the attn bit gets stuck, it's a similar problem. So allow messages in between flag fetches so the driver itself doesn't get stuck. This is a more general fix than the previous fix for the specific bad BMC, but should fix the more general issue of a BMC that won't stop saying it has data. This has been there from the beginning of the driver. It's not a bug per-se, but it is accounting for bugs in BMCs.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Linux | Linux Kernel | >= 2.6.12.1, < 5.10.258 | — |
| Linux | Linux Kernel | >= 5.11, < 5.15.209 | — |
| Linux | Linux Kernel | >= 5.16, < 6.1.175 | — |
| Linux | Linux Kernel | >= 6.2, < 6.6.140 | — |
| Linux | Linux Kernel | >= 6.7, < 6.12.88 | — |
| Linux | Linux Kernel | >= 6.13, < 6.18.30 | — |
| Linux | Linux Kernel | >= 6.19, < 7.0.7 | — |
| Linux | Linux Kernel | 2.6.12 | — |
| Linux | Linux Kernel | 7.1 | Rc1 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-46177?
How severe is CVE-2026-46177?
How do I fix CVE-2026-46177?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-46171In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2026-46172In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2026-46173In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-46174In the Linux kernel, the following vulnerability has been re…8.8
- CVE-2026-46175In the Linux kernel, the following vulnerability has been re…7.1
- CVE-2026-46176In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-46178In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-46179In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2026-46180In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-46181In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-46182In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2026-46183In the Linux kernel, the following vulnerability has been re…7.8
Are you affected by CVE-2026-46177?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
