Use-after-free in Linux kernel - CVE-2026-46058
Published: May 28, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a race condition leading to use-after-free in the amphion vpu driver m2m handling when releasing and scheduling the same m2m context concurrently. A local user can trigger concurrent job abort and device run operations to cause a denial of service.
The issue can result in a kernel panic due to a read from freed memory.
How to mitigate CVE-2026-46058
Sources
- https://git.kernel.org/stable/c/42dc622776f3ce1a6c31b13bdc686f7295e3b323
- https://git.kernel.org/stable/c/6be2cb75bc1300080cfc8051579f22efae9401f7
- https://git.kernel.org/stable/c/8cd35ceadcfc8c5da2eb7f7ce24525ce9d4ee62e
- https://git.kernel.org/stable/c/da4f46c5cf1d26e6b09418ad453e152f2e75a02c
- https://git.kernel.org/stable/c/fdc150dac1adb9a98be9d6956cff0348838b024a