THREAT OPS › Threat News › [NVD] CVE-2026-46306 (HIGH 7.5) — In the Linux kernel, the following vulnerability has been resolved:
flow_dissector: do not dissect PPPoE PFC frames
RFC 2516 Section 7 states that Protocol Field Compression (PFC) is NOT
RECOMMENDED for PPPoE. In practice, pppd does not support negotiating
PFC for PPPoE session
[NVD] CVE-2026-46306 (HIGH 7.5) — In the Linux kernel, the following vulnerability has been resolved: flow_dissector: do not dissect PPPoE PFC frames RFC 2516 Section 7 states that Protocol Field Compression (PFC) is NOT RECOMMENDED for PPPoE. In practice, pppd does not support negotiating PFC for PPPoE session
CVE-2026-46306 CVSS: 7.5 HIGH Published: 2026-06-08T17:16:49.383
In the Linux kernel, the following vulnerability has been resolved:
flow_dissector: do not dissect PPPoE PFC frames
RFC 2516 Section 7 states that Protocol Field Compression (PFC) is NOT RECOMMENDED for PPPoE. In practice, pppd does not support negotiating PFC for PPPoE sessions, and the flow dissector driver has assumed an uncomp
MITRE ATT&CK techniques
- CompressionT1027.015
Indicators of compromise
- CVE-2026-46306cve
- https://lore.kernel.org/r/20220630231016.GA392@debian.homeurl
- 20220630231016.ga392@debian.homeemail
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-46306