Answer in brief
CVE-2026-46040 records a Unknown severity vulnerability in inotify: fix watch count leak when fsnotify_add_inode_mark_locked() fails. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic), Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (generic), Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic), Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (generic), Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=1cce1eea0aff51201753fcaca421df825b0813b6 <3ab58cf42c46bf2366d2f55ae5c59299d5e178b7 || >=1cce1eea0aff51201753fcaca421df825b0813b6 <10edf7e0ffdc7faa18e2244b17722c1b882b8273 || >=1cce1eea0aff51201753fcaca421df825b0813b6 <3ad9ccea1b25435f6179b57aa891960beb7ce8f9 || >=1cce1eea0aff51201753fcaca421df825b0813b6 <8bcc1cd237ab5ccfdd102869fa031c541943cf40 || >=1cce1eea0aff51201753fcaca421df825b0813b6 <73ddc8518a32baff6bc17afda4ee1ebae5b4ed12 || >=1cce1eea0aff51201753fcaca421df825b0813b6 <fdaa42ca370d056428e5e171247c8fdce8dff36a || >=1cce1eea0aff51201753fcaca421df825b0813b6 <9e48844f708eb48bae4e79cb21edc097c966306d || >=1cce1eea0aff51201753fcaca421df825b0813b6 <6a320935fa4293e9e599ec9f85dc9eb3be7029f8 | 3ab58cf42c46bf2366d2f55ae5c59299d5e178b7, 10edf7e0ffdc7faa18e2244b17722c1b882b8273, 3ad9ccea1b25435f6179b57aa891960beb7ce8f9, 8bcc1cd237ab5ccfdd102869fa031c541943cf40, 73ddc8518a32baff6bc17afda4ee1ebae5b4ed12, fdaa42ca370d056428e5e171247c8fdce8dff36a, 9e48844f708eb48bae4e79cb21edc097c966306d, 6a320935fa4293e9e599ec9f85dc9eb3be7029f8 |
| Linux/Linuxgeneric | 4.11 | Not reported |
| Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFPgeneric | >=V3.1.6 <* | * |
| Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFPgeneric | >=V3.1.6 <* | * |
| Siemens/SIPLUS S7-1500 CPU 1518-4 PN/DP MFPgeneric | >=V3.1.6 <* | * |
Published upstream
May 27, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 8, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 8, 2026
In the Linux kernel, the following vulnerability has been resolved: inotify: fix watch count leak when fsnotify_add_inode_mark_locked() fails When fsnotify_add_inode_mark_locked() fails in inotify_new_watch(), the error path calls inotify_remove_from_idr() but does not call dec_inotify_watches() to undo the preceding inc_inotify_watches(). This leaks a watch count, and repeated failures can exhaust the max_user_watches limit with -ENOSPC even when no watches are active. Prior to commit 1cce1eea0aff ("inotify: Convert to using per-namespace limits"), the watch count was incremented after fsnotify_add_mark_locked() succeeded, so this path was not affected. The conversion moved inc_inotify_watches() before the mark insertion without adding the corresponding rollback. Add the missing dec_inotify_watches() call in the error path.
Quoted source text, attributed separately from HOL analysis.