Use-after-free in Linux kernel - CVE-2026-46065
Published: May 28, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in fbdev deferred I/O handling when accessing a memory mapping after device hot-unplug. A local user can keep an active mapping of graphics memory and access it after hot-unplug to cause a denial of service.
Access to the invalidated mapping may result in a SIGBUS signal.
How to mitigate CVE-2026-46065
Sources
- https://git.kernel.org/stable/c/25c2b77bc463f29ee71a54b883548baf9386a0db
- https://git.kernel.org/stable/c/2a40f8bc9bb713329f1c35ffc199ee961a7135b0
- https://git.kernel.org/stable/c/2b53d3a52e8e5403a4f4fb57ac6cad3fd2cb1066
- https://git.kernel.org/stable/c/9ded47ad003f09a94b6a710b5c47f4aa5ceb7429
- https://git.kernel.org/stable/c/a0aafb421dd15e935d81543152617f2742cefa70