Use-after-free in Linux kernel - CVE-2026-45837
Published: May 28, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to use-after-free in arena_vm_close and bpf_arena_free_pages when handling inherited arena VMAs after a fork. A local user can trigger a stale VMA reference by calling bpf_arena_free_pages() in a child process after the parent unmaps the arena to cause a denial of service.
The issue occurs when an arena VMA is inherited across fork and the child retains a pointer to the parent VMA.
Affected software
Ubuntu
linux (Ubuntu package)
linux-ibm (Ubuntu package)
linux-oem-7.0 (Ubuntu package)
linux-azure (Ubuntu package)
linux-aws (Ubuntu package)
How to mitigate CVE-2026-45837
linux (Ubuntu package) - addressed in versions 7.0.0-28.28, 7.0.0-28.28.1, 7.0.0-1003.4, 7.0.0-1008.8
linux-ibm (Ubuntu package) - addressed in versions 7.0.0-1008.8, 7.0.0-1010.10
linux-oem-7.0 (Ubuntu package) - update to 7.0.0-1009.9
linux-azure (Ubuntu package) - addressed in versions 7.0.0-1009.9, 7.0.0-1010.10
linux-aws (Ubuntu package) - addressed in versions 7.0.0-1009.9, 7.0.0-1015.15