Exposure of Resource to Wrong Sphere in Linux kernel - CVE-2026-46174
Published: May 29, 2026
Vulnerability identifier: #VU133010
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2026-46174
CWE-ID: CWE-668
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vendor: Linux Foundation
Affected software:
Linux kernel
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause instruction corruption.
The vulnerability exists due to improper isolation of shared resources in Zen2 op cache when executing code on the system. A local user can run code locally to cause instruction corruption.
How to mitigate CVE-2026-46174
Install security update from vendor's repository.
Sources
- https://git.kernel.org/stable/c/1cd85a19748b2407830376a5cbae5c0f126016e5
- https://git.kernel.org/stable/c/1e23b30a80b14e5764657401ee2cca030525ae8e
- https://git.kernel.org/stable/c/251497955f2314cd39d43191e81c6151dead4c7b
- https://git.kernel.org/stable/c/28f5ed477eef166d678d6966762cbc1de9b4f436
- https://git.kernel.org/stable/c/9109489cc8c34e50d15575a3d1ff82af586bc1aa
- https://git.kernel.org/stable/c/c21b90f77687075115d989e53a8ec5e2bb427ab1
- https://git.kernel.org/stable/c/f5bc3aef7df46eaaf423d7413ab8833f704ae576
- https://git.kernel.org/stable/c/ff6fc65b3bf73acc5ee71919154d830ad5431362